Code Injection Vulnerability in Robot Operating System's Command-Line Tool
CVE-2024-39835
Key Information:
- Vendor
- CVE Published:
- 17 July 2025
What is CVE-2024-39835?
A code injection flaw has been discovered in the 'roslaunch' command-line tool of the Robot Operating System (ROS), which affects several distributions including Noetic Ninjemys and earlier versions. This vulnerability stems from the improper handling of user-supplied parameters in the eval() method, enabling attackers to introduce and execute arbitrary Python code. By exploiting this flaw through crafted parameter inputs, an adversary could potentially gain unauthorized control over the system and compromise its integrity, thus posing a significant risk to applications leveraging ROS for robotic frameworks and automation.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Robot Operating System (ROS) Linux Noetic Ninjemys
Robot Operating System (ROS) Linux Melodic Morenia
Robot Operating System (ROS) Linux Kinetic Kame
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
