CVE-2025-67906: XSS
Published Dec 15, 2025
·Updated
In MISP before 2.5.28, app/View/Elements/Workflows/executionPath.ctp allows XSS in the workflow execution path.
Affected Software
2 affected components
Misp Misp<2.5.28
Misp-project Misp<2.5.28
Remediation
Event History
Dec 15, 2025
CVE Published
via MITRE·03:25 AM
Data Sourced
via MITRE·03:25 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·04:15 AM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-67906?
CVE-2025-67906 is considered a high severity vulnerability due to its potential for Cross-Site Scripting (XSS) attacks.
2
How do I fix CVE-2025-67906?
To fix CVE-2025-67906, upgrade your MISP installation to version 2.5.28 or later.
3
What is the impact of CVE-2025-67906 on affected systems?
CVE-2025-67906 allows attackers to execute malicious scripts within the context of a user's browser, potentially leading to data theft and session hijacking.
4
Which versions of MISP are affected by CVE-2025-67906?
CVE-2025-67906 affects MISP versions prior to 2.5.28.
5
Is CVE-2025-67906 a remote vulnerability?
Yes, CVE-2025-67906 can be exploited remotely without requiring authentication.