FixVibe

high

Authenticated Command Injection in MISP STIX Import (CVE-2018-19908)

A critical command injection vulnerability was identified in MISP versions 2.4.9x prior to 2.4.99. The flaw exists within the STIX 1 import functionality where unescaped filename strings are used to construct shell commands, allowing authenticated attackers to achieve remote code execution.

CVE-2018-19908CWE-78

Impact

An authenticated attacker can execute operating-system commands through the vulnerable MISP STIX import path [S1]. That can lead to server compromise, access to sensitive threat intelligence data, and movement into adjacent infrastructure.

Root Cause

The issue is in the MISP STIX 1 import logic in app/Model/Event.php [S1]. A filename used during import can flow into shell-command construction without sufficient escaping in affected versions [S1].

Covered by FixVibe

FixVibe's GitHub repo scans flag MISP repositories that contain the affected STIX import code, so maintainers can patch before deployment.

Fix

Upgrade MISP to version 2.4.99 or later [S1]. If maintaining a fork, make sure shell arguments are escaped with safe APIs such as escapeshellarg() or, preferably, replace shell execution with native PHP handling for STIX processing.

Authenticated Command Injection in MISP STIX Import (CVE-2018-19908)