Unsafe use of eval() method in ros2 topic hz tool
Published Sep 28, 2026
8.6
HIGHCVSS 4.0
EPSS 0.16%
Description
A code injection vulnerability has been discovered in the Robot Operating System 2 (ROS 2) 'ros2topic' command-line tool, affecting all ROS 2 distributions from Crystal Clemmys up to and including Lyrical Luth and Rolling Ridley. The vulnerability lies in the 'hz' verb, which reports the publishing rate of a topic and accepts a user-provided Python expression via the --filter option. This input is passed directly to the eval() function without sanitization, allowing a local user to craft and execute arbitrary code.
Affected products
-
- Version Crystal ClemmysStatusaffectedConstraints-
- Version Dashing DiademataStatusaffectedConstraints-
- Version Eloquent ElusorStatusaffectedConstraints-
- Version Foxy FitzroyStatusaffectedConstraints-
- Version Galactic GeocheloneStatusaffectedConstraints-
- Version Humble HawksbillStatusaffectedConstraints-
- Version Iron IrwiniStatusaffectedConstraints-
- Version Jazzy JaliscoStatusaffectedConstraints-
- Version Kilted KaijuStatusaffectedConstraints-
- Version Lyrical LuthStatusaffectedConstraints-
- Version Rolling RidleyStatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Open Source Robotics Foundation | Robot Operating System 2 (ROS 2) | unaffected |
|
No data.
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
Vendor solution
No fixed release is available at the time of publication. A fix is proposed upstream in https://github.com/ros2/ros2cli/pull/1001.
Metrics
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
No CVSS v3.0 score for this CVE.
No CVSS v2.0 score for this CVE.
This CVE is not in the KEV list.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
NoneAutomatable
NoTechnical Impact
TotalDecision
n/aAssessed Sep 30, 2026 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
Not enough EPSS history yet for a chart. At least two recorded scores are needed.
Percentile over time
Not enough EPSS history yet for a chart. At least two recorded scores are needed.
References (2)
- https://github.com/ros2/ros2cli/pull/1001 patch
- https://github.com/ros2/ros2cli/pull/133#discussion_r223081766 issue-tracking
| Link | Providers | Tags |
|---|---|---|
| https://github.com/ros2/ros2cli/pull/1001 | patch | |
| https://github.com/ros2/ros2cli/pull/133#discussion_r223081766 | issue-tracking |
Change history (0)
No recorded changes yet.