Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

Open Source Robotics Foundation — Vulnerabilities & Security Advisories 6

Browse all 6 CVE security advisories affecting Open Source Robotics Foundation. AI-powered Chinese analysis, POCs, and references for each vulnerability.

The Open Source Robotics Foundation develops and supports open-source software frameworks for robotics research and development, with its ROS (Robot Operating System) platform being widely adopted in industrial and research settings. Historically, common vulnerabilities include remote code execution, cross-site scripting, and privilege escalation, often stemming from insufficient input validation and insecure default configurations. While no major security incidents have been publicly documented, the organization's six recorded CVEs highlight potential risks in middleware components and communication protocols. Security characteristics include a community-driven development model with varying patch response times, which may lead to delayed vulnerability remediation in critical infrastructure deployments.

Top products by Open Source Robotics Foundation: Robot Operating System (ROS)
CVE IDTitleCVSSSeverityPublished
CVE-2025-3753 Unsafe use of eval() method in rosbag tool — Robot Operating System (ROS)CWE-95 7.8 High2025-07-17
CVE-2024-41921 Unsafe use of eval() method in rostopic echo tool — Robot Operating System (ROS)CWE-95 7.8 High2025-07-17
CVE-2024-41148 Unsafe use of eval() method in rostopic hz tool — Robot Operating System (ROS)CWE-95 7.8 High2025-07-17
CVE-2024-39835 Unsafe use of eval() method in roslaunch tool — Robot Operating System (ROS)CWE-95 7.8 High2025-07-17
CVE-2024-39289 Unsafe use of eval() method in rosparam tool — Robot Operating System (ROS)CWE-95 7.8 High2025-07-17
CVE-2024-39780 Use of unsafe yaml load in dynparam — Robot Operating System (ROS)CWE-502 7.8 High2025-04-02

This page lists every published CVE security advisory associated with Open Source Robotics Foundation. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.