PT-2026-64167 · Gnuplot+1 · Gnuplot+1

·

CVE-2026-60122

·

Published

2026-07-23

·

Updated

2026-09-08

CVSS v4.0

8.5

High

VectorAV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions gpsd versions prior to 3.27.6
Description The gpsprof utility contains a code injection flaw. An attacker controlling GPS input data can execute arbitrary OS commands by injecting malicious content into the SKY.satellites[].used field. This field is inserted without sanitization into a gnuplot heredoc data block. By supplying a used value containing the string EOD, an attacker can terminate the heredoc prematurely and append gnuplot system() calls, leading to command execution as the user running gpsprof when the script is processed by gnuplot in polar mode.
Recommendations Update to the version containing commit 4c06658 or later.

Exploit

Fix

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2026:65162
ALSA-2026:65606
CVE-2026-60122

Affected Products

Gnuplot
Gpsd