Code Injection Vulnerability in Robot Operating System 2 Command-Line Tool
CVE-2024-42002
Key Information:
- Vendor
- CVE Published:
- 28 September 2026
What is CVE-2024-42002?
A code injection vulnerability has been identified in the Robot Operating System 2 (ROS 2) 'ros2topic' command-line tool. This issue affects all ROS 2 distributions from Crystal Clemmys through to Lyrical Luth and Rolling Ridley. The vulnerability stems from the 'hz' verb, which reports the publishing rate of a topic. It accepts a user-provided Python expression via the --filter option and directly passes this input to the eval() function without any sanitization. As a result, a local user can craft and execute arbitrary code by manipulating the input, creating significant security risks for ROS 2 environments.
Affected Version(s)
Robot Operating System 2 (ROS 2) Linux Rolling Ridley
Robot Operating System 2 (ROS 2) Linux Lyrical Luth
Robot Operating System 2 (ROS 2) Linux Kilted Kaiju
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
