Recent Advisories

Severity ID Title Vendor Product Date Type
HIGH 7.5 CVE-2026-54358

MISP organization administrators can target site administrator accounts for password reset_CVE-2026-54358

An incorrect authorization vulnerability in MISP allows an organization administrator to target site administrator accounts belonging to the same o...

misp misp CVE
MEDIUM 5 CVE-2026-54055

Kitty has an Arbitrary File Write via Symlink Race Condition in File Transmission Protocol_CVE-2026-54055

Kitty is a cross-platform GPU based terminal. In versions prior to 0.47.2, a local privilege escalation vulnerability exists in kitty's file transm...

kovidgoyal kitty < 0.47.2 CVE
HIGH 7.8 CVE-2026-42851

@kitty-edit DCS + –color=geninclude vulnerable to Unauthenticated in-process RCE_CVE-2026-42851

Kitty is a cross-platform GPU based terminal. In versions prior to 0.47.0, a program able to write bytes to a kitty terminal — a remote SSH peer, a...

kovidgoyal kitty < 0.47.0 CVE
HIGH 7.4 CVE-2026-42850

Kitty has a shell command injection_CVE-2026-42850

Kitty is a cross-platform GPU based terminal. In versions prior to 0.47.0, it is possible to inject commands within the subshell through kitty erro...

kovidgoyal kitty < 0.47.0 CVE
MEDIUM 6.1 CVE-2026-54397

MISP event editing allows unauthorized assignment to undisclosed sharing groups_CVE-2026-54397

A vulnerability in MISP’s non-REST event editing path allowed an authenticated user with event edit permissions to manipulate the submitted form da...

misp misp CVE
MEDIUM 5.3 CVE-2026-54396

MISP AuthKey edit endpoint allows authenticated user email enumeration_CVE-2026-54396

An information disclosure vulnerability exists in the MISP AuthKey edit functionality. When a validation error occurs during an AuthKey edit reques...

misp misp CVE
MEDIUM 5.3 CVE-2026-54395

MISP UiBeta event index reflected XSS in advanced filter popup_CVE-2026-54395

MISP contains a reflected cross-site scripting vulnerability in the UiBeta event index view. The urlparams value is inserted into an inline JavaScr...

misp misp CVE
MEDIUM 5.3 CVE-2026-54394

MISP organisation logo path traversal allows retrieval of arbitrary PNG/SVG files_CVE-2026-54394

MISP contains a path traversal vulnerability in OrganisationsController::getOrgLogo. The vulnerable code builds organisation logo file paths using ...

misp misp CVE
MEDIUM 5.1 CVE-2026-54393

MISP Overmind theme stored XSS via unvalidated homepage setting_CVE-2026-54393

A stored cross-site scripting vulnerability exists in MISP when the Overmind theme is used. The setHomePage endpoint previously saved the user-cont...

misp misp CVE
MEDIUM 5.3 CVE-2026-54362

MISP template builder exposes non-visible custom galaxies across organisations_CVE-2026-54362

An incorrect visibility condition in the MISP event template builder allowed authenticated non-site-admin users to view galaxies that should not ha...

misp misp CVE