CVE-2025-3753
Unsafe use of eval() method in rosbag tool
Vexday Risk Score
21Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 7.8EPSS 0.2%KEV nãoPoC —Nuclei —Metasploit —Patch —
Lifecycle
17 Jul 2025Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
A code execution vulnerability has been identified in the Robot Operating System (ROS) 'rosbag' tool, affecting ROS distributions Noetic Ninjemys and earlier. The vulnerability arises from the use of the eval() function to process unsanitized, user-supplied input in the 'rosbag filter' command. This flaw enables attackers to craft and execute arbitrary Python code.
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Affected products
Open Source Robotics Foundation · Robot Operating System (ROS)Want to know if your infrastructure is exposed to this?
Talk to TrueHacking →References
https://www.ros.org/blog/noetic-eol/