Code Execution Vulnerability in Robot Operating System Tool by Open Robotics
CVE-2024-39289
Key Information:
- Vendor
- CVE Published:
- 17 July 2025
What is CVE-2024-39289?
A code execution vulnerability exists in the 'rosparam' tool of the Robot Operating System (ROS), which affects several ROS distributions, including Noetic Ninjemys and earlier versions. This vulnerability arises from the unsafe implementation of the eval() function, allowing attackers to exploit unsanitized user-input parameter values, particularly through specialized converters for angle representations in radians. By leveraging this flaw, an attacker can execute arbitrary Python code on vulnerable systems, posing a significant security risk.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Robot Operating System (ROS) Linux Noetic Ninjemys
Robot Operating System (ROS) Linux Melodic Morenia
Robot Operating System (ROS) Linux Kinetic Kame
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
