Code Injection Vulnerability in gpsd's gpsprof Utility
CVE-2026-60122

8.5HIGH

Key Information:

Vendor

Gpsd

Status
Vendor
CVE Published:
23 July 2026

What is CVE-2026-60122?

The gpsd software package, specifically version 3.27.5, has a code injection vulnerability found in the gpsprof utility. This flaw enables an attacker who has control over GPS input data to execute arbitrary operating system commands. The attack is possible due to unsanitized input in the SKY.satellites[].used field, which can be manipulated to include a string that prematurely terminates a heredoc in a gnuplot data block. By appending specific gnuplot system commands, an attacker can gain the ability to execute commands as the user running the gpsprof utility when the generated plot script is processed by gnuplot in polar mode.

Affected Version(s)

gpsd 0 <= 3.27.5

gpsd 0 <= 3.27.5

gpsd 5a9c44a42136b9bb98d460a8a716e9fd344a8d93

References

CVSS V4

Score:
8.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

CuB3y0nd
VulnCheck
.