← Back

CVE-2025-3753

nvd nist
Published: Jul 17, 2025Modified: Aug 26, 2025

JSON object

Loading...
7.8
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Exploitability: 1.8 / Impact: 5.9
Source: security@ubuntu.com (Secondary)

Description

A code execution vulnerability has been identified in the Robot Operating System (ROS) 'rosbag' tool, affecting ROS distributions Noetic Ninjemys and earlier. The vulnerability arises from the use of the eval() function to process unsanitized, user-supplied input in the 'rosbag filter' command. This flaw enables attackers to craft and execute arbitrary Python code.

Affected (4)

1 product
Robot Operating System
Configuration A
4 vulnerable
Vulnerable SoftwareAffected Versions
Openrobotics
Version indigo_igloo
Version kinetic_kame
Version melodic_morenia
Version noetic_ninjemys

References (1)

Source: security@ubuntu.com
Product

Timeline

No history available yet.