CVE-2026-85453

MOOS core-moos through 10.4.0 fails to escape database contents when rendering MOOSDB HTTP pages, allowing attackers to inject malicious scripts. Any MOOS publisher can set variable values containing script payloads that execute in the browser of operators viewing the web interface.
Configurations

No configuration.

History

No history.

Information

Published : 2026-09-03 23:17

Updated : 2026-09-14 14:17


NVD link : CVE-2026-85453

Mitre link : CVE-2026-85453

CVE.ORG link : CVE-2026-85453


JSON object : View

Products Affected

No product.

CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')