๐Ÿ” CVE Alert

CVE-2024-42002

HIGH 8.4

Unsafe use of eval() method in ros2 topic hz tool

CVSS Score
8.4
EPSS Score
0.0%
EPSS Percentile
0th

A code injection vulnerability has been discovered in the Robot Operating System 2 (ROS 2) 'ros2topic' command-line tool, affecting all ROS 2 distributions from Crystal Clemmys up to and including Lyrical Luth and Rolling Ridley. The vulnerability lies in the 'hz' verb, which reports the publishing rate of a topic and accepts a user-provided Python expression via the --filter option. This input is passed directly to the eval() function without sanitization, allowing a local user to craft and execute arbitrary code.

CWE CWE-95 CWE-94
Vendor open source robotics foundation
Product robot operating system 2 (ros 2)
Published Sep 28, 2026
Stay Ahead of the Next One

Get instant alerts for open source robotics foundation robot operating system 2 (ros 2)

Be the first to know when new high vulnerabilities affecting open source robotics foundation robot operating system 2 (ros 2) are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Vector
Local
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High

Affected Versions

Open Source Robotics Foundation / Robot Operating System 2 (ROS 2)
Rolling Ridley Lyrical Luth Kilted Kaiju Jazzy Jalisco Iron Irwini Humble Hawksbill Galactic Geochelone Foxy Fitzroy Eloquent Elusor Dashing Diademata Crystal Clemmys

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/ros2/ros2cli/pull/1001 github.com: https://github.com/ros2/ros2cli/pull/133#discussion_r223081766

Credits

Florencia Cabral Berenfus, Ubuntu Robotics Team