STIX2 Parser Confusion and Mass Assignment Allow Unauthorized MISP Attribute Metadata Injection in misp-stix library
A vulnerability in misp-stix could allow a crafted STIX document to influence security-sensitive MISP attribute metadata during import. The STIX import logic automatically selected between the internal MISP parser and the external STIX parser based on metadata contained in the STIX document itself. For STIX2, the presence of MISP-specific tool labels could cause a document to be classified as originating from MISP; similarly, STIX1 relied on the document title. These classification indicators are fully controlled …
Analyzer searches are accepted only from validated browser forms. CVE identifiers also have strict read-only /vulnerability/ permalinks for sharing.
View:
2026-08-23 07:13 CESTIntelligence refreshed
1unique CVEs queried and enriched
1unique CVEs correlated to this result
1unique advisories correlated
12intelligence collections queried
Affected software, operating systems and devices
2 software records
NVD/CVE catalog 1CISA Vulnrichment 1
Vendor:
softwareAffected range: All listed or unspecified versions
Developer provenance is shown per record. Duplicate records corroborated by several feeds retain every contributing source and extraction method. Matching scanned assets will be added through the reverse device index.
Exploit probability: Estimated exploitation probability 0.29% — percentile 21.8%.
Vulnerability summary: STIX2 Parser Confusion and Mass Assignment Allow Unauthorized MISP Attribute Metadata Injection in misp-stix library
A vulnerability in misp-stix could allow a crafted STIX document to influence security-sensitive MISP attribute metadata during import. The STIX import logic automatically selected between the internal MISP parser and the external STIX parser based on metadata contained in the STIX document itself. For STIX2, the presence of MISP-specific tool labels could cause a document to be classified as originating from MISP; similarly, STIX1 relied on the document title. These classification indicators are fully controlled by the STIX producer and therefore cannot constitute a trusted indication of the document's origin. The accompanying fix explicitly notes that the parser choice was previously based solely on labels or header titles that any producer could write, and introduces an explicit classification parameter allowing callers to override this detection. When STIX2 content was handled as an internal MISP export, attributes contained in an x-misp-object were converted by copying the comple…
Only sources that directly identify or describe the queried CVE are shown here. Historical examples from MITRE CWE definitions are kept in the weakness section and are not presented as related CVEs.
Correlated from multiple vulnerability, exploitation, advisory, package and affected-product intelligence collections.
Coverage note: Scantide correlates multiple public and locally indexed intelligence sources, but no dataset or matching process is complete. Results may omit software, dependencies, affected versions or advisories, and related records do not by themselves prove that a specific installation is vulnerable. Confirm important findings against vendor guidance and the installed product and version.