CVE-2024-42002 PUBLISHED

Unsafe use of eval() method in ros2 topic hz tool

Assigner: canonical
Reserved: 01.08.2024 Published: 28.09.2026 Updated: 28.09.2026

A code injection vulnerability has been discovered in the Robot Operating System 2 (ROS 2) 'ros2topic' command-line tool, affecting all ROS 2 distributions from Crystal Clemmys up to and including Lyrical Luth and Rolling Ridley. The vulnerability lies in the 'hz' verb, which reports the publishing rate of a topic and accepts a user-provided Python expression via the --filter option. This input is passed directly to the eval() function without sanitization, allowing a local user to craft and execute arbitrary code.

Metrics

CVSS Vector: CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
CVSS Score: 8.6

Product Status

Vendor Open Source Robotics Foundation
Product Robot Operating System 2 (ROS 2)
Versions Default: unaffected
  • Version Rolling Ridley is affected
  • Version Lyrical Luth is affected
  • Version Kilted Kaiju is affected
  • Version Jazzy Jalisco is affected
  • Version Iron Irwini is affected
  • Version Humble Hawksbill is affected
  • Version Galactic Geochelone is affected
  • Version Foxy Fitzroy is affected
  • Version Eloquent Elusor is affected
  • Version Dashing Diademata is affected
  • Version Crystal Clemmys is affected

Workarounds

Do not pass untrusted or unreviewed input to the --filter option of 'ros2 topic hz'.

Solutions

No fixed release is available at the time of publication. A fix is proposed upstream in https://github.com/ros2/ros2cli/pull/1001.

Credits

  • Florencia Cabral Berenfus, Ubuntu Robotics Team finder

References

Problem Types

  • CWE-95 Improper neutralization of directives in dynamically evaluated code ('eval injection') CWE
  • CWE-94 Improper Control of Generation of Code ('Code Injection') CWE

Impacts

  • CAPEC-242 Code Injection