Stored Cross-Site Scripting Vulnerability in MOOS Core-MOOS Product
CVE-2026-85453

5.3MEDIUM

Key Information:

Vendor

Themoos

Status
Vendor
CVE Published:
3 September 2026

What is CVE-2026-85453?

The MOOS core-moos version 10.4.0 and earlier is susceptible to a stored cross-site scripting vulnerability that allows malicious actors to inject harmful scripts. This issue arises when database contents are rendered on MOOSDB HTTP pages without adequate escaping, enabling any MOOS publisher to set variable values that contain script payloads. As a result, these scripts can execute in the browsers of operators when they access the compromised web interface, leading to potential data theft or unauthorized actions.

Affected Version(s)

core-moos 0 <= 10.4.0

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Vlatko Kosturjak
.