MOOS core-moos through 10.4.0 fails to validate client...
High severity
Unreviewed
Published
Sep 4, 2026
to the GitHub Advisory Database
•
Updated Sep 4, 2026
Description
Published by the National Vulnerability Database
Sep 3, 2026
Published to the GitHub Advisory Database
Sep 4, 2026
Last updated
Sep 4, 2026
MOOS core-moos through 10.4.0 fails to validate client identity in MOOSDB message processing, allowing authenticated attackers to attribute writes to other clients by supplying arbitrary source identifiers in serialized messages. Attackers can forge message origins and cancel third-party subscriptions by exploiting the disconnect between authenticated connection identity and wire-supplied source attribution.
References