PT-2026-102382 · Ros2 · Ros2

CVE-2024-42002

·

Published

2026-09-28

·

Updated

2026-09-28

CVSS v3.1

8.4

High

VectorAV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Robot Operating System 2 (ROS 2) versions Crystal Clemmys through Rolling Ridley
Description The ros2topic command-line tool contains a code injection flaw within the hz verb, which is used to report the publishing rate of a topic. The tool accepts a user-provided Python expression through the --filter option and passes it directly to the eval() function without proper sanitization. This allows a local user to execute arbitrary code by crafting a malicious expression.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability. Avoid using the --filter option in the ros2topic hz command to minimize the risk of exploitation.

Eval Injection

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-42002

Affected Products

Ros2