Executive brief
MOOS-IvP is a software framework for autonomous robotic platforms, particularly marine vehicles. The alogsplit utility, used to process and split log files, contains a command injection vulnerability in its path handling that allows attackers to execute arbitrary commands with the privileges of the operator running the tool by embedding shell metacharacters in log file paths or directory parameters.
Technical details
The vulnerability exists in the SplitHandler::handlePreCheckSplitDir() function within alogsplit, which fails to properly sanitize shell metacharacters in log file pathnames and the --dir parameter. Attackers can exploit this via a network or local vector by providing specially crafted log file names or directory paths containing shell syntax (e.g., semicolons, pipes, command substitution). The unsanitized input is passed to shell execution functions, allowing remote code execution with the privileges of the alogsplit operator. No special authentication or user interaction is required beyond providing a malicious input path. Patches should be available in versions after 24.8.1.
Affected products
- MOOS-IvP MOOS-IvP through 24.8.1
Timeline
- 2026-09-03: disclosed