CVE-2026-15541: Will-Moss Isaiah
High severity, CVSS 7.3. EPSS: 0.5% chance of exploitation in the next 30 days.
A flaw has been found in will-moss Isaiah up to 1.36.9. The impacted element is the function Server.Handle of the file app/server/server/server.go of the component Master Websocket Handler. Executing a manipulation of the argument Agent can lead to missing authorization. It is possible to launch the attack remotely. The pull request to fix this issue awaits acceptance.
Affected products
- Will-Moss Isaiah: version 1.36.0 only; version 1.36.1 only; version 1.36.2 only; version 1.36.3 only; version 1.36.4 only; version 1.36.5 only; …
Published 2026-07-13. Last modified 2026-07-13.