CVE-2024-42002
Unsafe use of eval() method in ros2 topic hz tool
CVSS Score
8.4
EPSS Score
0.0%
EPSS Percentile
0th
A code injection vulnerability has been discovered in the Robot Operating System 2 (ROS 2) 'ros2topic' command-line tool, affecting all ROS 2 distributions from Crystal Clemmys up to and including Lyrical Luth and Rolling Ridley. The vulnerability lies in the 'hz' verb, which reports the publishing rate of a topic and accepts a user-provided Python expression via the --filter option. This input is passed directly to the eval() function without sanitization, allowing a local user to craft and execute arbitrary code.
| CWE | CWE-95 CWE-94 |
| Vendor | open source robotics foundation |
| Product | robot operating system 2 (ros 2) |
| Published | Sep 28, 2026 |
Stay Ahead of the Next One
Get instant alerts for open source robotics foundation robot operating system 2 (ros 2)
Be the first to know when new high vulnerabilities affecting open source robotics foundation robot operating system 2 (ros 2) are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Attack Vector
Local
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
Affected Versions
Open Source Robotics Foundation / Robot Operating System 2 (ROS 2)
Rolling Ridley Lyrical Luth Kilted Kaiju Jazzy Jalisco Iron Irwini Humble Hawksbill Galactic Geochelone Foxy Fitzroy Eloquent Elusor Dashing Diademata Crystal Clemmys
References
Credits
Florencia Cabral Berenfus, Ubuntu Robotics Team