Description
A flaw has been found in will-moss Isaiah up to 1.36.9. The impacted element is the function Server.Handle of the file app/server/server/server.go of the component Master Websocket Handler. Executing a manipulation of the argument Agent can lead to missing authorization. It is possible to launch the attack remotely. The pull request to fix this issue awaits acceptance.
Published: 2026-07-13
Score: 6.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a flaw in the Server.Handle function of the Master WebSocket Handler in will-moss Isaiah. Manipulation of the Agent argument results in missing authorization checks, allowing an unauthorized entity to potentially perform privileged operations. The weakness is classified as CWE-862 and CWE-863.

Affected Systems

The flaw affects will-moss Isaiah versions up to and including 1.36.9. Any installation running these or earlier versions is vulnerable until a patch that implements proper Agent validation is released. The issue originates in app/server/server/server.go within the Master WebSocket Handler component.

Risk and Exploitability

The vulnerability carries a CVSS score of 6.9, indicating medium-to-high severity. The EPSS score of < 1% suggests a very low likelihood of exploitation, and the vulnerability is not listed in the CISA KEV catalog. The description states that a remote attack is possible; based on the information provided, it is inferred that an attacker could manipulate the Agent argument through the WebSocket interface to bypass authorization, but the exact method is not detailed.

Generated by OpenCVE AI on July 31, 2026 at 12:16 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply an updated release of will-moss Isaiah that includes the Agent validation once the fix is merged.
  • Restrict access to the WebSocket endpoint using firewall rules or a reverse proxy to limit exposure to trusted IP ranges.
  • Ensure that any incoming Agent arguments are validated against the authenticated user context before executing privileged operations.

Generated by OpenCVE AI on July 31, 2026 at 12:16 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 13 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 13 Jul 2026 07:45:00 +0000

Type Values Removed Values Added
Description A flaw has been found in will-moss Isaiah up to 1.36.9. The impacted element is the function Server.Handle of the file app/server/server/server.go of the component Master Websocket Handler. Executing a manipulation of the argument Agent can lead to missing authorization. It is possible to launch the attack remotely. The pull request to fix this issue awaits acceptance.
Title will-moss Isaiah Master Websocket server.go Server.Handle authorization
First Time appeared Will-moss
Will-moss isaiah
Weaknesses CWE-862
CWE-863
CPEs cpe:2.3:a:will-moss:isaiah:*:*:*:*:*:*:*:*
Vendors & Products Will-moss
Will-moss isaiah
References
Metrics cvssV2_0

{'score': 7.5, 'vector': 'AV:N/AC:L/Au:N/C:P/I:P/A:P/E:ND/RL:ND/RC:UR'}

cvssV3_0

{'score': 7.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:X/RL:X/RC:R'}

cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:X/RL:X/RC:R'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X'}


Subscriptions

Will-moss Isaiah
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-07-13T14:28:26.935Z

Reserved: 2026-07-12T18:12:28.084Z

Link: CVE-2026-15541

cve-icon Vulnrichment

Updated: 2026-07-13T14:28:22.312Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T12:30:16Z

Weaknesses