PT-2025-29952 · Unknown+1 · Robot Operating System+1

Published

2025-07-17

·

Updated

2025-07-18

·

CVE-2024-41148

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Robot Operating System (ROS) versions prior to Noetic Ninjemys
Description A code injection issue exists in the 'rostopic' command-line tool. The vulnerability is located in the 'hz' verb, which uses the --filter option to accept a user-provided Python expression. This input is directly passed to the eval() function without proper sanitization, potentially allowing a local user to execute arbitrary code.
Recommendations Update to ROS Noetic Ninjemys or a later version.

Fix

Code Injection

Eval Injection

Weakness Enumeration

Related Identifiers

CVE-2024-41148

Affected Products

Debian
Robot Operating System