Summary
CVE-2026-77751 is a path traversal vulnerability (CWE-22) in misp-stix, the STIX 2 import/export component of the MISP threat intelligence platform. It affects handling of object template names during STIX 2 import and MISP-to-STIX 2 export, and carries a HIGH severity score of 8.8. A remote, unauthenticated attacker can craft a malicious object name to escape the intended template directory and cause disclosure of local files accessible to the MISP process.
Technical details
- Root cause: Object template names supplied in STIX/MISP content are joined directly into a filesystem path (template directory + object name +
definition.json) without restricting the name to a safe, single path component. - Trigger conditions: An attacker-controlled object name (e.g., a custom STIX object’s
x_misp_namefield) containing path separators or../traversal sequences reaches the template-resolution logic during STIX 2 import. - Persistence risk: A malicious object name can be stored in a MISP event and later reprocessed during STIX 2 export, meaning content introduced under one security context can trigger file access later, potentially under a different or more privileged process.
- Attack vector: Network — no authentication or user interaction required beyond submitting/importing crafted STIX content.
- Impact: Disclosure of arbitrary local
definition.json-style files accessible to the process, whose contents may be interpreted as a template and copied into the converted object, along with modification of the resulting object’s metadata/semantics.
Affected software
- MISP
misp-stixcomponent: versions 0 through 2026.7.8 (all versions prior to the fix)
Severity
- CVSS Score: 8.8 (High)
- Vector:
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N
Mitigation and recommended actions
- Immediate: Upgrade
misp-stixto a version that includes the fix applied in commitsa8b6808danda0f54070, which validate object template names against a safe pattern (letters, digits, hyphens, underscores only) and route invalid names to a genericunknown-templateobject instead of resolving them from the filesystem. - If immediate patching is not possible: Restrict which users/systems can submit STIX 2 content for import, and monitor MISP logs for objects converted to
unknown-templateor template resolution warnings, which may indicate attempted exploitation. Limit filesystem permissions available to the MISP/misp-stix process to reduce the impact of any successful traversal.

