CVE-2025-66386: Misp
Medium severity, CVSS 4.1. EPSS: 0.3% chance of exploitation in the next 30 days.
app/Model/EventReport.php in MISP before 2.5.27 allows path traversal in view picture for a site-admin.
Affected products
- Misp Misp: before 2.5.27 (fixed in 2.5.27)
Published 2025-11-28. Last modified 2026-06-17.