js/event-graph.js in MISP prior to 2.4.169 allows XSS via the event-graph relationship tooltip.
misp-project malware information sharing platform