GHSA-h9vw-jjgr-29wcHigh

MISP contains an improper input validation vulnerability in the decaying model import...

Published
October 2, 2026
Last Modified
October 2, 2026

🔗 CVE IDs covered (1)

📋 Description

MISP contains an improper input validation vulnerability in the decaying model import functionality. The import endpoint was intended to create a new decaying model belonging exclusively to the importing user's organisation, with the default flag forced to off.

However, the application stripped only the top-level id and uuid fields and pinned org_id and default on the outer array before saving the data flat. A user with decaying-model permissions could supply a nested model key carrying its own primary key, organisation identifier, and default flag, which bypassed those guards during the save operation.

Impact:

  • A user with perm_decaying could overwrite an existing decaying model belonging to another organisation in place, altering its name, formula, parameters, or ownership.

  • A user could create or modify a model flagged as the organisation default, affecting scoring behaviour for other users.

  • A user could reassign a model's organisation to an arbitrary value.

Preconditions:

  • Authenticated user with decaying-model permission (perm_decaying).

  • Network access to the MISP instance.

Affected: <2.5.48.

🔗 References (3)