CVE-2026-85439

Summary

MOOS-IvP through 24.8.1 contains a remote code execution vulnerability in alogsplit's SplitHandler::handlePreCheckSplitDir() function that fails to sanitize shell metacharacters in log file pathnames. Attackers can embed shell syntax in log file names or the –dir parameter to execute arbitrary commands with the privileges of the operator running alogsplit.

Affected Software

VendorProductVersion RangeStatus
moos-ivpmoos-ivp0 <= 24.8.1affected

Weaknesses

  • CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

References