Path Traversal Vulnerability in MOOS-IvP Affecting Windows Systems
CVE-2026-85456
6.8MEDIUM
What is CVE-2026-85456?
The MOOS-IvP application, up to version 24.8.1, contains a vulnerability in its SplitHandler component that fails to properly validate variable names extracted from alog files. This oversight allows attackers to craft malicious alog files that include backslash sequences in variable names, enabling them to escape the designated output directory. Consequently, this may permit unauthorized file writing to arbitrary locations on Windows systems, posing a significant security risk.
Affected Version(s)
moos-ivp 0 <= 24.8.1
