VORANT. Threat Intelligence Sign in Get the full feed

MISP patches XSS flaws in 2.5.10 release

low vulnerability technology

MISP 2.5.10 and 2.4.208 fix stored XSS vulnerabilities and insecure defaults reported by Cparta Cyber Defense researcher Patrik Wallström.

MISP, the widely used open-source threat intelligence platform, released versions 2.5.10 and 2.4.208 addressing several security issues alongside functional improvements. The security fixes include stored XSS vulnerabilities in Galaxy killchain elements and icon elements, potentially insecure defaults in the uploadFile/deleteFile type parameter (exploitable only under misconfiguration), and exposure of S3 access keys in plugin settings. These issues were reported by Patrik Wallström of Cparta Cyber Defense.

Beyond the security patches, the release improves authentication plugin handling for OIDC and LDAP, adds LDAP filter escaping, introduces validation for S3 bucket operations, and improves sync warning logging and workflow editor caching behavior. The MISP project recommends all users, particularly those relying on authentication plugins, remote sync, S3 storage, or Galaxy features, upgrade promptly and review configurations for secure defaults.

No evidence of active exploitation is presented; this is a routine vendor patch release addressing responsibly disclosed vulnerabilities in a defensive security tool.

Source reporting: https://www.misp-project.org/2025/04/04/misp.2.5.10.and.2.4.208.released.html

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free