CVE-2025-66386: Misp

Medium severity, CVSS 4.1. EPSS: 0.3% chance of exploitation in the next 30 days.

app/Model/EventReport.php in MISP before 2.5.27 allows path traversal in view picture for a site-admin.

Affected products

  • Misp Misp: before 2.5.27 (fixed in 2.5.27)

Published 2025-11-28. Last modified 2026-06-17.