Impact
The vulnerability is a flaw in the Server.Handle function of the Master WebSocket Handler in will-moss Isaiah. Manipulation of the Agent argument results in missing authorization checks, allowing an unauthorized entity to potentially perform privileged operations. The weakness is classified as CWE-862 and CWE-863.
Affected Systems
The flaw affects will-moss Isaiah versions up to and including 1.36.9. Any installation running these or earlier versions is vulnerable until a patch that implements proper Agent validation is released. The issue originates in app/server/server/server.go within the Master WebSocket Handler component.
Risk and Exploitability
The vulnerability carries a CVSS score of 6.9, indicating medium-to-high severity. The EPSS score of < 1% suggests a very low likelihood of exploitation, and the vulnerability is not listed in the CISA KEV catalog. The description states that a remote attack is possible; based on the information provided, it is inferred that an attacker could manipulate the Agent argument through the WebSocket interface to bypass authorization, but the exact method is not detailed.
OpenCVE Enrichment