VORANT. Threat Intelligence Sign in Get the full feed

MISP 2.5.10 patches stored XSS flaws

medium vulnerability technology

MISP released versions 2.5.10 and 2.4.208 fixing stored XSS vulnerabilities and insecure defaults reported by Cparta Cyber Defense.

MISP has released updates 2.5.10 and 2.4.208 addressing several security issues, most notably stored cross-site scripting (XSS) vulnerabilities found in Galaxy killchain elements and icon elements. These flaws were reported by Patrik Wallström of Cparta Cyber Defense. The update also fixes potentially insecure defaults in the uploadFile/deleteFile type parameter, though this requires an existing misconfiguration to be exploitable, and ensures S3 access keys are no longer exposed in plugin settings.

Beyond the security fixes, the release includes improvements to authentication plugin handling (OIDC, LDAP), remote sync validation and logging, warning list comment handling, and workflow editor caching behavior. The MISP project recommends all users upgrade, particularly those relying on authentication plugins, remote sync, S3 storage, or Galaxy features, and to review configurations for secure defaults.

This is a routine maintenance and security patch release for the MISP threat intelligence platform with no evidence of active exploitation in the wild. The vulnerabilities were responsibly disclosed and patched through normal vendor channels.

Source reporting: https://www.misp-project.org/2025/04/04/misp.2.5.10.and.2.4.208.released.html

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free