← Vulnerability feed

Vulnerability record · CVE-2020-10289 · published 20 August 2020

CVE-2020-10289: Openrobotics robot operating system improper input validation vulnerability

Openrobotics · Robot Operating System

Use of unsafe yaml load. Allows instantiation of arbitrary objects. The flaw itself is caused by an unsafe parsing of YAML values which happens whenever an action message is processed to be sent, and allows for the creation of Python objects. Through this flaw in the ROS core package of actionlib, an attacker with local or remote access can make the ROS Master, execute arbitrary code in Python form. Consider yaml.safe_load() instead. Located first in actionlib/tools/library.py:132. See links for more info on the bug.

8.8 CVSS 3.1 High EPSS 2.0% · top 20.2% CWE-20 · Improper input validationCWE-502 · Deserialization of untrusted data
8.8CVSS 3.1 base score, v2 6.5
2.0%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

Use of unsafe yaml load. Allows instantiation of arbitrary objects. The flaw itself is caused by an unsafe parsing of YAML values which happens whenever an action message is processed to be sent, and allows for the creation of Python objects. Through this flaw in the ROS core package of actionlib, an attacker with local or remote access can make the ROS Master, execute arbitrary code in Python form. Consider yaml.safe_load() instead. Located first in actionlib/tools/library.py:132. See links for more info on the bug.

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
https://github.com/ros/actionlib/pull/171 PatchThird Party Advisory
https://github.com/ros/actionlib/pull/171 PatchThird Party Advisory

Track CVE-2020-10289 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2024-39780Openrobotics robot operating system improper input validation vulnerabilityA YAML deserialization vulnerability was found in the Robot Operating System (ROS) 'dynparam', a command-line tool for getting, setting, and deleting…EPSS 0.40%9.8CVE-2024-41649Openrobotics robot operating system vulnerabilityInsecure Permissions vulnerability in Open Robotics Robotic Operating System 2 ROS2 navigation2 v.humble allows an attacker to execute arbitrary code…EPSS 0.70%9.8CVE-2024-44852Openrobotics robot operating system vulnerabilityOpen Robotics Robotic Operating System 2 ROS2 navigation2 v.humble was discovered to contain a segmentation violation via the component theta_star::T…EPSS 0.60%9.8CVE-2024-41650Openrobotics robot operating system vulnerabilityInsecure Permissions vulnerability in Open Robotics Robotic Operating System 2 ROS2 navigation2 v.humble allows an attacker to execute arbitrary code…EPSS 0.48%9.8CVE-2024-38926Openrobotics robot operating system use after free vulnerabilityOpen Robotics Robotic Operating System 2 (ROS2) and Nav2 humble versions were discovered to contain a use-after-free via the nav2_amcl process. This …EPSS 0.59%9.8CVE-2024-41648Openrobotics robot operating system vulnerabilityInsecure Permissions vulnerability in Open Robotics Robotic Operating System 2 ROS2 navigation2 v.humble allows an attacker to execute arbitrary code…EPSS 0.48%9.8CVE-2024-41646Openrobotics robot operating system vulnerabilityInsecure Permissions vulnerability in Open Robotics Robotic Operating System 2 ROS2 navigation2 v.humble allows an attacker to execute arbitrary code…EPSS 0.70%9.8CVE-2024-38927Openrobotics robot operating system use after free vulnerabilityOpen Robotics Robotic Operating System 2 (ROS2) and Nav2 humble versions were discovered to contain a use-after-free via the nav2_amcl process. This …EPSS 0.59%

Source: NIST National Vulnerability Database (record CVE-2020-10289), CISA KEV, FIRST EPSS (scores of 2026-10-08). This page is refreshed as NVD updates the record.