In MISP before 2.5.28, app/View/Elements/Workflows/executionPath.ctp allows XSS in the workflow execution path.
References
| Link | Resource |
|---|---|
| https://github.com/MISP/MISP/commit/1f39deb572da7ecb5855e30ff3cc8cbcaa0c1054 | Patch |
| https://github.com/MISP/MISP/compare/v2.5.27...v2.5.28 | Release Notes |
| https://github.com/franckferman/CVE-2025-67906 | Third Party Advisory |
| https://github.com/franckferman/GCVE-1-2025-0030 | Third Party Advisory |
| https://vulnerability.circl.lu/vuln/gcve-1-2025-0031 | Third Party Advisory |
| https://github.com/franckferman/CVE-2025-67906 | Third Party Advisory |
Configurations
History
18 Dec 2025, 18:06
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Misp misp
Misp |
|
| CPE | cpe:2.3:a:misp:misp:*:*:*:*:*:*:*:* | |
| References | () https://github.com/MISP/MISP/commit/1f39deb572da7ecb5855e30ff3cc8cbcaa0c1054 - Patch | |
| References | () https://github.com/MISP/MISP/compare/v2.5.27...v2.5.28 - Release Notes | |
| References | () https://github.com/franckferman/GCVE-1-2025-0030 - Third Party Advisory | |
| References | () https://vulnerability.circl.lu/vuln/gcve-1-2025-0031 - Third Party Advisory | |
| References | () https://github.com/franckferman/CVE-2025-67906 - Third Party Advisory |
15 Dec 2025, 16:15
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
15 Dec 2025, 04:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-12-15 04:15
Updated : 2025-12-21 01:15
NVD link : CVE-2025-67906
Mitre link : CVE-2025-67906
CVE.ORG link : CVE-2025-67906
JSON object : View
Products Affected
misp
- misp
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
