PT-2026-102382 · Ros2 · Ros2
CVE-2024-42002
·
Published
2026-09-28
·
Updated
2026-09-28
CVSS v3.1
8.4
High
| Vector | AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Robot Operating System 2 (ROS 2) versions Crystal Clemmys through Rolling Ridley
Description
The
ros2topic command-line tool contains a code injection flaw within the hz verb, which is used to report the publishing rate of a topic. The tool accepts a user-provided Python expression through the --filter option and passes it directly to the eval() function without proper sanitization. This allows a local user to execute arbitrary code by crafting a malicious expression.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Avoid using the
--filter option in the ros2topic hz command to minimize the risk of exploitation.Eval Injection
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Ros2