{"id":79577,"date":"2026-06-10T19:47:16","date_gmt":"2026-06-10T16:17:16","guid":{"rendered":"https:\/\/afaghhosting.net\/blog\/cve-2026-53693-misp-bsimvis-stored-cross-site-scripting-in-tag-and-cluster-rendering-paths-via-unescaped-tag-metadata-and-ui-labels\/"},"modified":"2026-06-10T19:47:16","modified_gmt":"2026-06-10T16:17:16","slug":"cve-2026-53693-misp-bsimvis-stored-cross-site-scripting-in-tag-and-cluster-rendering-paths-via-unescaped-tag-metadata-and-ui-labels","status":"publish","type":"post","link":"https:\/\/afaghhosting.net\/blog\/cve-2026-53693-misp-bsimvis-stored-cross-site-scripting-in-tag-and-cluster-rendering-paths-via-unescaped-tag-metadata-and-ui-labels\/","title":{"rendered":"CVE-2026-53693 &#8211; MISP BSimVis stored cross-site scripting in tag and cluster rendering paths via unescaped tag metadata and UI labels"},"content":{"rendered":"<p>CVE ID :CVE-2026-53693<\/p>\n<p>  Published : June 10, 2026, 4:17 p.m. | 22\u00a0minutes ago<\/p>\n<p>  Description :A stored cross-site scripting vulnerability existed in MISP\u00a0BSimVis tag rendering code. Several client-side rendering paths interpolated tag names, collection names, entity identifiers, cluster names, and tag metadata directly into HTML, HTML attributes, inline JavaScript event handlers, and CSS style values without context-appropriate escaping. The patch adds shared escaping helpers for HTML, attributes, JavaScript strings, and CSS color validation, then applies them across tag badges, tooltips, context menus, cluster cards, autocomplete suggestions, and dynamically inserted tag cards.<\/p>\n<p>An attacker able to create or influence stored tag or metadata values could inject a crafted payload that is later rendered in another user\u2019s browser. Successful exploitation could execute arbitrary JavaScript in the victim\u2019s session when they view affected BSimVis pages, potentially allowing the attacker to perform actions as the victim, read data available to the victim, or alter displayed application content.<\/p>\n<p>This issue affects MISP bsimvis: through v0.2.0.<\/p>\n<p>  Severity: 6.9 | MEDIUM<\/p>\n<p>  Visit the link for more details, such as CVSS details, affected products, timeline, and more&#8230;\u00a0<\/p>\n","protected":false},"excerpt":{"rendered":"<p>CVE ID :CVE-2026-53693 Published : June 10, 2026, 4:17 p.m. | 22\u00a0minutes ago Description :A stored cross-site scripting vulnerability existed in MISP\u00a0BSimVis tag rendering code. Several client-side rendering paths interpolated tag names, collection names, entity identifiers, cluster names, and tag metadata directly into HTML, HTML attributes, inline JavaScript event handlers, and CSS style values without &hellip;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[26],"tags":[],"class_list":["post-79577","post","type-post","status-publish","format-standard","hentry","category-vulnerability"],"_links":{"self":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts\/79577","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/comments?post=79577"}],"version-history":[{"count":0,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts\/79577\/revisions"}],"wp:attachment":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/media?parent=79577"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/categories?post=79577"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/tags?post=79577"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}