---
id: CVE-2026-85456
title: >-
  MOOS-IvP through 24.8.1 fails to properly validate variable names extracted
  from alog files in the SplitHandler, allowing attackers to write files outside
  the split directory
summary: >-
  MOOS-IvP through 24.8.1 fails to properly validate variable names extracted
  from alog files in the SplitHandler, allowing attackers to write files outside
  the split directory. Attackers can supply crafted alog files with backslash
  sequen…
severity: medium
cvss: 5.5
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N'
cwe:
  - CWE-22
published: '2026-09-03'
updated: '2026-09-08'
sourceUpdated: '2026-09-08T20:07:17.943'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-85456'
references:
  - url: 'https://github.com/moos-ivp/moos-ivp'
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/moos-ivp/moos-ivp/blob/1de9ae146cd63c209e8c3fd81611a4ed2472971b/ivp/src/lib_logutils/SplitHandler.cpp#L189
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/moos-ivp/moos-ivp/commit/6f0619e905b325d6b88f76425673045c6e4f6f94
    label: disclosure@vulncheck.com
  - url: 'https://github.com/moos-ivp/moos-ivp/pull/137'
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/moos-ivp-through-24.8.1-alog-splitting-path-traversal-on-windows
    label: disclosure@vulncheck.com
tags:
  - nvd
epss: 0.00184
epssPercentile: 0.07064
ingestedAt: '2026-09-08T20:10:03.162Z'
---

## Overview

MOOS-IvP through 24.8.1 fails to properly validate variable names extracted from alog files in the SplitHandler, allowing attackers to write files outside the split directory. Attackers can supply crafted alog files with backslash sequences in variable names to escape the output directory and append to arbitrary files on Windows systems.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
