PT-2025-29953 · Unknown+1 · Robot Operating System+1

Published

2025-07-17

·

Updated

2025-07-18

·

CVE-2024-41921

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Robot Operating System (ROS) versions prior to Noetic Ninjemys
Description A code injection issue exists in the rostopic command-line tool within the Robot Operating System (ROS). The vulnerability is located in the echo verb, which utilizes the --filter option to accept a user-provided Python expression. This input is directly passed to the eval() function without proper sanitization, potentially enabling a local user to execute arbitrary code.
Recommendations Update to ROS Noetic Ninjemys or a later version to address this issue.

Fix

Code Injection

Eval Injection

Weakness Enumeration

Related Identifiers

CVE-2024-41921

Affected Products

Debian
Robot Operating System