← Vulnerability feed

Vulnerability record · CVE-2024-25626 · published 19 February 2024

CVE-2024-25626: Linuxfoundation yocto os command injection vulnerability

Linuxfoundation · Yocto

Yocto Project is an open source collaboration project that helps developers create custom Linux-based systems regardless of the hardware architecture. In Yocto Projects Bitbake before 2.6.2 (before and included Yocto Project 4.3.1), with the Toaster server (included in bitbake) running, missing input validation allows an attacker to perform a remote code execution in the server's shell via a crafted HTTP request. Authentication is not necessary. Toaster server execution has to be specifically run and is not the default for Bitbake command line builds, it is only used for the Toaster web based user interface to Bitbake. The fix has been backported to the bitbake included with Yocto Project 5.0, 3.1.31, 4.0.16, and 4.3.2.

9.8 CVSS 3.1 Critical EPSS 1.2% · top 32.7% CWE-78 · OS command injection
9.8CVSS 3.1 base score
1.2%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

Yocto Project is an open source collaboration project that helps developers create custom Linux-based systems regardless of the hardware architecture. In Yocto Projects Bitbake before 2.6.2 (before and included Yocto Project 4.3.1), with the Toaster server (included in bitbake) running, missing input validation allows an attacker to perform a remote code execution in the server's shell via a crafted HTTP request. Authentication is not necessary. Toaster server execution has to be specifically run and is not the default for Bitbake command line builds, it is only used for the Toaster web based user interface to Bitbake. The fix has been backported to the bitbake included with Yocto Project 5.0, 3.1.31, 4.0.16, and 4.3.2.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2024-25626 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2024-20148Linuxfoundation yocto out-of-bounds write vulnerabilityIn wlan STA FW, there is a possible out of bounds write due to improper input validation. This could lead to remote (proximal/adjacent) code executio…EPSS 0.26%9.8CVE-2024-20080Linuxfoundation yocto improper certificate validation vulnerabilityIn gnss service, there is a possible escalation of privilege due to improper certificate validation. This could lead to remote escalation of privileg…EPSS 0.29%8.8CVE-2024-20040Linuxfoundation yocto out-of-bounds write vulnerabilityIn wlan firmware, there is a possible out of bounds write due to improper input validation. This could lead to remote escalation of privilege with no…EPSS 0.18%8.4CVE-2024-20104Linuxfoundation yocto out-of-bounds write vulnerabilityIn da, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional exe…EPSS 0.09%8.4CVE-2024-20053Linuxfoundation yocto out-of-bounds write vulnerabilityIn flashc, there is a possible out of bounds write due to an uncaught exception. This could lead to local escalation of privilege with System executi…EPSS 0.09%8.1CVE-2024-20146Linuxfoundation yocto out-of-bounds write vulnerabilityIn wlan STA driver, there is a possible out of bounds write due to improper input validation. This could lead to remote (proximal/adjacent) code exec…EPSS 0.14%7.8CVE-2025-20705Linuxfoundation yocto use after free vulnerabilityIn monitor_hang, there is a possible memory corruption due to use after free. This could lead to local escalation of privilege if a malicious actor h…EPSS 0.09%7.5CVE-2025-61611Linuxfoundation yocto improper input validation vulnerabilityIn modem, there is a possible improper input validation. This could lead to remote denial of service with no additional execution privileges needed..EPSS 0.56%

Source: NIST National Vulnerability Database (record CVE-2024-25626), CISA KEV, FIRST EPSS (scores of 2026-09-28). This page is refreshed as NVD updates the record.