CVE-2024-37860: Open Robotics NAV2 Humble
High severity, CVSS 7.3. EPSS: 0.3% chance of exploitation in the next 30 days.
Buffer Overflow vulnerability in Open Robotic Operating System 2 ROS2 navigation2- ROS2-humble&& navigation2-humble allows a local attacker to execute arbitrary code via a crafted .yaml file to the nav2_amcl process
Affected products
- Open Robotics NAV2 Humble: any version
- Open Robotics ROS2 Humble: any version
- Open Robotics ROS2 NAVIGATION2: any version
Published 2024-12-05. Last modified 2026-06-17.