Answer in brief
CVE-2024-42002 records a High severity (CVSS 8.6) vulnerability in Unsafe use of eval() method in ros2 topic hz tool. The current sources do not mark it as known exploited. The current feed maps Open Source Robotics Foundation/Robot Operating System 2 (ROS 2) (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
CVSS is 8.6. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Open Source Robotics Foundation/Robot Operating System 2 (ROS 2) (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Open Source Robotics Foundation/Robot Operating System 2 (ROS 2)generic | Rolling Ridley || Lyrical Luth || Kilted Kaiju || Jazzy Jalisco || Iron Irwini || Humble Hawksbill || Galactic Geochelone || Foxy Fitzroy || Eloquent Elusor || Dashing Diademata || Crystal Clemmys | Not reported |
Published upstream
Sep 28, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Sep 28, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Sep 28, 2026
A code injection vulnerability has been discovered in the Robot Operating System 2 (ROS 2) 'ros2topic' command-line tool, affecting all ROS 2 distributions from Crystal Clemmys up to and including Lyrical Luth and Rolling Ridley. The vulnerability lies in the 'hz' verb, which reports the publishing rate of a topic and accepts a user-provided Python expression via the --filter option. This input is passed directly to the eval() function without sanitization, allowing a local user to craft and execute arbitrary code.
Quoted source text, attributed separately from HOL analysis.