Skip to content

Commit d37f6b4

Browse files
committed
chg: [security] GCVE-1-2026-0003 added
1 parent 2d112a8 commit d37f6b4

1 file changed

Lines changed: 1 addition & 0 deletions

File tree

content/security.md

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -137,6 +137,7 @@ We firmly believe that, even though unfortunately it is often not regarded as co
137137
- [GCVE-1-2025-0019](https://vulnerability.circl.lu/vuln/gcve-1-2025-0019) < MISP 2.5.26 - The “view picture” functionality in EventReport for site-administrators suffered from a path traversal vulnerability.
138138
- [GCVE-1-2025-0030](https://vulnerability.circl.lu/vuln/gcve-1-2025-0030) < MISP 2.5.27 - A cross-site scripting (XSS) vulnerability in the “actions” table element template in app/View/Elements/genericElements/IndexTable/Fields/actions.ctp allows an attacker to inject arbitrary JavaScript code into the generated HTML.
139139
- [GCVE-1-2025-0031](https://vulnerability.circl.lu/vuln/gcve-1-2025-0031) < MISP 2.5.27 - A cross-site scripting (XSS) vulnerability was identified in the workflow execution-path view in app/View/Elements/Workflows/executionPath.ctp.
140+
- [GCVE-1-2025-0032](https://vulnerability.circl.lu/vuln/gcve-1-2026-0003) < MISP 2.5.32 - Stored/Reflected XSS via Unsanitized Parameters in URL Generation and JavaScript Context.
140141

141142
## PGP Key
142143

0 commit comments

Comments
 (0)