CyberRota Analysis
AI-GeneratedThe vulnerability exists in the 'ros2topic' command-line tool of the Robot Operating System 2 (ROS 2), affecting all distributions from Crystal Clemmys to Rolling Ridley. It allows local users to inject arbitrary code through the unsanitized user input in the --filter option, posing a significant risk of code execution. Organizations utilizing ROS 2 should prioritize patching this vulnerability to mitigate potential exploitation risks.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
A code injection vulnerability has been discovered in the Robot Operating System 2 (ROS 2) 'ros2topic' command-line tool, affecting all ROS 2 distributions from Crystal Clemmys up to and including Lyrical Luth and Rolling Ridley. The vulnerability lies in the 'hz' verb, which reports the publishing rate of a topic and accepts a user-provided Python expression via the --filter option. This input is passed directly to the eval() function without sanitization, allowing a local user to craft and execute arbitrary code.