Back

HIGH

Unsafe use of eval() method in ros2 topic hz tool

Published Sep 28, 2026

Description

A code injection vulnerability has been discovered in the Robot Operating System 2 (ROS 2) 'ros2topic' command-line tool, affecting all ROS 2 distributions from Crystal Clemmys up to and including Lyrical Luth and Rolling Ridley. The vulnerability lies in the 'hz' verb, which reports the publishing rate of a topic and accepts a user-provided Python expression via the --filter option. This input is passed directly to the eval() function without sanitization, allowing a local user to craft and execute arbitrary code.

Affected products

Remediation

Vendor solution

No fixed release is available at the time of publication. A fix is proposed upstream in https://github.com/ros2/ros2cli/pull/1001.

Metrics

References (2)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner canonical
Published Sep 28, 2026
Updated Sep 30, 2026
Reserved Aug 1, 2024
CISA Vulnrichment
Updated Sep 30, 2026
NVD
Status Received
Modified Sep 28, 2026
Red Hat
Severity n/a
Public date n/a