MISP 2.5.37 patches SQL injection, privesc bugs
MISP 2.5.37 ships a new Event Templating system and fixes three vulnerabilities, including a blind SQL injection and an auth-key privilege escalation to site admin.
The MISP project released version 2.5.37, primarily notable for a ground-up rewrite of its event templating engine, a new dedicated `suricata` attribute type, continued UI migration to the Overmind (Bootstrap 5) theme, and a switch to the upstream STIX 2 library. Alongside these feature changes, the release addresses three security issues that were responsibly disclosed and assigned GCVE identifiers.
The most significant fix addresses a blind SQL injection vulnerability where user-controlled `order`/`sort` parameters on `POST /events/index` and `GET /shadow_attributes/index` reached the SQL `ORDER BY` clause without validation, allowing any authenticated user — including read-only accounts — to extract arbitrary database content. A second issue allowed an organisation admin sharing an org with a site admin to reset that site admin's authentication key via `POST /users/resetauthkey/<id>` and retrieve the new key in the response, enabling privilege escalation to full site-admin access. A third, lower-severity fix enforces RFC 4122 validation on Collection UUIDs. All three were reported by external researchers (Jeroen Gui and Jeroen Pinoy) and are fixed in this release with no indication of in-the-wild exploitation.
Given MISP's broad deployment across threat intelligence teams, CERTs, and information-sharing communities, administrators should prioritize upgrading to 2.5.37, particularly to close the privilege-escalation and SQL injection paths, both of which are exploitable by any authenticated, low-privileged user.
Source reporting: https://www.misp-project.org/2026/04/29/misp.2.5.37.released.html
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free