OCTOBER 8, 2026
Live Feed
Back to database
Case File

CVE-2024-42002

HIGH · CVSS 8.4 EPSS 0.16% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-28 · Last synced 2026-10-08

CyberRota Analysis

AI-Generated

The vulnerability exists in the 'ros2topic' command-line tool of the Robot Operating System 2 (ROS 2), affecting all distributions from Crystal Clemmys to Rolling Ridley. It allows local users to inject arbitrary code through the unsanitized user input in the --filter option, posing a significant risk of code execution. Organizations utilizing ROS 2 should prioritize patching this vulnerability to mitigate potential exploitation risks.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2024-42002
Severity
HIGH
CVSS
8.4
EPSS
0.16%

Original NVD Description

A code injection vulnerability has been discovered in the Robot Operating System 2 (ROS 2) 'ros2topic' command-line tool, affecting all ROS 2 distributions from Crystal Clemmys up to and including Lyrical Luth and Rolling Ridley. The vulnerability lies in the 'hz' verb, which reports the publishing rate of a topic and accepts a user-provided Python expression via the --filter option. This input is passed directly to the eval() function without sanitization, allowing a local user to craft and execute arbitrary code.