Metrics
Affected Vendors & Products
No advisories yet.
Solution
No fixed release is available at the time of publication. A fix is proposed upstream in https://github.com/ros2/ros2cli/pull/1001.
Workaround
Do not pass untrusted or unreviewed input to the --filter option of 'ros2 topic hz'.
Mon, 28 Sep 2026 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A code injection vulnerability has been discovered in the Robot Operating System 2 (ROS 2) 'ros2topic' command-line tool, affecting all ROS 2 distributions from Crystal Clemmys up to and including Lyrical Luth and Rolling Ridley. The vulnerability lies in the 'hz' verb, which reports the publishing rate of a topic and accepts a user-provided Python expression via the --filter option. This input is passed directly to the eval() function without sanitization, allowing a local user to craft and execute arbitrary code. | |
| Title | Unsafe use of eval() method in ros2 topic hz tool | |
| Weaknesses | CWE-94 CWE-95 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: canonical
Published:
Updated: 2026-09-28T21:38:08.369Z
Reserved: 2024-08-01T12:00:12.183Z
Link: CVE-2024-42002
No data.
Status : Received
Published: 2026-09-28T22:17:28.617
Modified: 2026-09-28T22:17:28.617
Link: CVE-2024-42002
No data.
OpenCVE Enrichment
No data.