← Vulnerability feed

Vulnerability record · CVE-2024-39780 · published 2 April 2025

CVE-2024-39780: Openrobotics robot operating system improper input validation vulnerability

Openrobotics · Robot Operating System

A YAML deserialization vulnerability was found in the Robot Operating System (ROS) 'dynparam', a command-line tool for getting, setting, and deleting parameters of a dynamically configurable node, affecting ROS distributions Noetic and earlier. The issue is caused by the use of the yaml.load() function in the 'set' and 'get' verbs, and allows for the creation of arbitrary Python objects. Through this flaw, a local or remote user can craft and execute arbitrary Python code.

9.8 CVSS 3.1 Critical EPSS 0.39% · top 69.6% CWE-20 · Improper input validationCWE-502 · Deserialization of untrusted data
9.8CVSS 3.1 base score
0.39%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
1References
17 Jun 2026Last modified by NVD

Description

A YAML deserialization vulnerability was found in the Robot Operating System (ROS) 'dynparam', a command-line tool for getting, setting, and deleting parameters of a dynamically configurable node, affecting ROS distributions Noetic and earlier. The issue is caused by the use of the yaml.load() function in the 'set' and 'get' verbs, and allows for the creation of arbitrary Python objects. Through this flaw, a local or remote user can craft and execute arbitrary Python code.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2024-39780 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2024-41649Openrobotics robot operating system vulnerabilityInsecure Permissions vulnerability in Open Robotics Robotic Operating System 2 ROS2 navigation2 v.humble allows an attacker to execute arbitrary code…EPSS 0.70%9.8CVE-2024-41650Openrobotics robot operating system vulnerabilityInsecure Permissions vulnerability in Open Robotics Robotic Operating System 2 ROS2 navigation2 v.humble allows an attacker to execute arbitrary code…EPSS 0.48%9.8CVE-2024-44852Openrobotics robot operating system vulnerabilityOpen Robotics Robotic Operating System 2 ROS2 navigation2 v.humble was discovered to contain a segmentation violation via the component theta_star::T…EPSS 0.60%9.8CVE-2024-38925Openrobotics robot operating system use after free vulnerabilityOpen Robotics Robotic Operating System 2 (ROS2) and Nav2 humble versions were discovered to contain a use-after-free via the nav2_amcl process. This …EPSS 0.59%9.8CVE-2024-38926Openrobotics robot operating system use after free vulnerabilityOpen Robotics Robotic Operating System 2 (ROS2) and Nav2 humble versions were discovered to contain a use-after-free via the nav2_amcl process. This …EPSS 0.59%9.8CVE-2024-38927Openrobotics robot operating system use after free vulnerabilityOpen Robotics Robotic Operating System 2 (ROS2) and Nav2 humble versions were discovered to contain a use-after-free via the nav2_amcl process. This …EPSS 0.59%9.8CVE-2024-41644Openrobotics robot operating system vulnerabilityInsecure Permissions vulnerability in Open Robotics Robotic Operating System 2 ROS2 navigation2 v.humble allows an attacker to execute arbitrary code…EPSS 0.70%9.8CVE-2024-41645Openrobotics robot operating system vulnerabilityInsecure Permissions vulnerability in Open Robotics Robotic Operating System 2 ROS2 navigation2 v.humble allows an attacker to execute arbitrary code…EPSS 0.70%

Source: NIST National Vulnerability Database (record CVE-2024-39780), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.