CVE-2026-85425
MOOS-IvP iSay through 24.8.1 contains a remote code execution vulnerability in the SAYMOOS variable handler that passes unsanitized text to a shell command. Attackers can publish SAYMOOS messages containing backticks or command substitution syntax to execute arbitrary commands as the iSay process user.
Package Versions Affected
Automatically patch vulnerabilities without upgrading
CVSS Version



Related Resources
References
https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/85xxx/CVE-2026-85425.json, https://nvd.nist.gov/vuln/detail/CVE-2026-85425, https://www.vulncheck.com/advisories/moos-ivp-through-24.8.1-isay-command-injection-via-say-moos, https://github.com/moos-ivp/moos-ivp/commit/ed3a44131fd3e5528602f20adc37ba82273c1cd8, https://github.com/moos-ivp/moos-ivp/pull/120, https://github.com/moos-ivp/moos-ivp, https://github.com/moos-ivp/moos-ivp/blob/1de9ae146cd63c209e8c3fd81611a4ed2472971b/ivp/src/iSay/Sayer.cpp#L416