PT-2025-29951 · Unknown+1 · Robot Operating System+1

Published

2025-07-17

·

Updated

2025-07-18

·

CVE-2024-39835

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Robot Operating System (ROS) versions prior to Noetic Ninjemys
Description A code injection issue exists in the 'roslaunch' command-line tool due to the use of the eval() method to process unsanitized parameter values within the substitution args mechanism. This allows attackers to execute arbitrary Python code.
Recommendations Update to a version of Robot Operating System (ROS) newer than Noetic Ninjemys.

Fix

Code Injection

Eval Injection

Weakness Enumeration

Related Identifiers

CVE-2024-39835

Affected Products

Debian
Robot Operating System