# MISP patches XSS flaws in 2.5.10 release

Published: 2025-04-04 · Severity: low · Sectors: technology
Canonical: https://vorant.io/reports/3a829e4d-fe8f-520b-a52b-8190fdfdeb3b/misp-patches-xss-flaws-in-2-5-10-release

> MISP 2.5.10 and 2.4.208 fix stored XSS vulnerabilities and insecure defaults reported by Cparta Cyber Defense researcher Patrik Wallström.

MISP, the widely used open-source threat intelligence platform, released versions 2.5.10 and 2.4.208 addressing several security issues alongside functional improvements. The security fixes include stored XSS vulnerabilities in Galaxy killchain elements and icon elements, potentially insecure defaults in the uploadFile/deleteFile type parameter (exploitable only under misconfiguration), and exposure of S3 access keys in plugin settings. These issues were reported by Patrik Wallström of Cparta Cyber Defense.

Beyond the security patches, the release improves authentication plugin handling for OIDC and LDAP, adds LDAP filter escaping, introduces validation for S3 bucket operations, and improves sync warning logging and workflow editor caching behavior. The MISP project recommends all users, particularly those relying on authentication plugins, remote sync, S3 storage, or Galaxy features, upgrade promptly and review configurations for secure defaults.

No evidence of active exploitation is presented; this is a routine vendor patch release addressing responsibly disclosed vulnerabilities in a defensive security tool.

Source reporting: https://www.misp-project.org/2025/04/04/misp.2.5.10.and.2.4.208.released.html

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/3a829e4d-fe8f-520b-a52b-8190fdfdeb3b/misp-patches-xss-flaws-in-2-5-10-release.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
