CVE-2026-85453
Received Received - Intake

MOOSDB XSS via Unescaped Database Contents in MOOS core-moos

Vulnerability report for CVE-2026-85453, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-03

Last updated on: 2026-09-03

Assigner: VulnCheck

Description

MOOS core-moos through 10.4.0 fails to escape database contents when rendering MOOSDB HTTP pages, allowing attackers to inject malicious scripts. Any MOOS publisher can set variable values containing script payloads that execute in the browser of operators viewing the web interface.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-03
Last Modified
2026-09-03
Generated
2026-09-04
AI Q&A
2026-09-04
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
moos core_moos to 10.4.0 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-79 The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

MOOS core-moos through version 10.4.0 does not properly escape database contents when rendering MOOSDB HTTP pages. This allows attackers who are MOOS publishers to inject malicious scripts into variable values. These scripts then execute in the browsers of operators viewing the web interface.

Detection Guidance

This vulnerability can be detected by inspecting MOOS core-moos HTTP pages for unescaped database contents. Check if any published variables contain script payloads by reviewing web interface outputs or logs for unexpected scripts or HTML injection attempts.

Impact Analysis

If you use MOOS core-moos through 10.4.0, attackers could inject malicious scripts into the web interface. This could lead to unauthorized actions, data theft, or session hijacking for operators viewing the interface.

Compliance Impact

This vulnerability could lead to unauthorized access or data breaches, which may violate GDPR (data protection) and HIPAA (health data privacy) requirements. Organizations must ensure proper security controls to maintain compliance.

Mitigation Strategies

Immediately update MOOS core-moos to the latest version beyond 10.4.0 to ensure proper escaping of database contents. Additionally, restrict access to the MOOSDB HTTP interface to trusted users only and monitor for any suspicious activity or unauthorized variable changes.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-85453. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart