---
id: CVE-2026-85453
title: >-
  MOOS core-moos through 10.4.0 fails to escape database contents when rendering
  MOOSDB HTTP pages, allowing attackers to inject malicious scripts
summary: >-
  MOOS core-moos through 10.4.0 fails to escape database contents when rendering
  MOOSDB HTTP pages, allowing attackers to inject malicious scripts. Any MOOS
  publisher can set variable values containing script payloads that execute in
  the b…
severity: medium
cvss: 6.1
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'
cwe:
  - CWE-79
vendor: themoos
product: core-moos
affected:
  - core-moos <= 10.4.0
published: '2026-09-03'
updated: '2026-09-14'
sourceUpdated: '2026-09-14T14:17:14.460'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-85453'
references:
  - url: 'https://github.com/themoos/core-moos'
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/themoos/core-moos/blob/ec9c77c68fcbdef8f5e4c60fe243acd223433f0c/Core/libMOOS/DB/HTTPConnection.cpp#L460
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/themoos/core-moos/commit/a3f26f099bb08decb143f704d8b1ca16ae405b44
    label: disclosure@vulncheck.com
  - url: 'https://github.com/themoos/core-moos/pull/78'
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/moos-core-moos-through-10.4.0-moosdb-http-pages-stored-cross-site-scripting
    label: disclosure@vulncheck.com
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-14T13:08:50.021920Z'
epss: 0.00338
epssPercentile: 0.2442
ingestedAt: '2026-09-08T20:10:03.162Z'
---

## Overview

MOOS core-moos through 10.4.0 fails to escape database contents when rendering MOOSDB HTTP pages, allowing attackers to inject malicious scripts. Any MOOS publisher can set variable values containing script payloads that execute in the browser of operators viewing the web interface.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
