Code Execution Vulnerability in Robot Operating System's rosbag Tool
CVE-2025-3753

7.8HIGH

What is CVE-2025-3753?

A significant vulnerability has been discovered in the Robot Operating System (ROS) related to the 'rosbag' tool, primarily impacting ROS distributions Noetic Ninjemys and prior versions. The issue stems from the use of the eval() function, which processes unsanitized input provided by users through the 'rosbag filter' command. This allows malicious users to execute arbitrary Python code, posing a serious security risk to systems relying on this functionality.

Affected Version(s)

Robot Operating System (ROS) Linux Noetic Ninjemys

Robot Operating System (ROS) Linux Melodic Morenia

Robot Operating System (ROS) Linux Kinetic Kame

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Giuseppe Barbieri, Ubuntu Robotics Team
.
CVE-2025-3753 : Code Execution Vulnerability in Robot Operating System's rosbag Tool