9.1
CVE-2026-46621
- EPSS 1%
- Veröffentlicht 16.07.2026 16:07:38
- Zuletzt bearbeitet 20.07.2026 01:46:21
- CVE-Watchlists
- Unerledigt
Yamcs: Authenticated Remote Code Execution (RCE) via Jython Algorithm Code Injection
Yamcs is a mission control framework. Prior to 5.12.7, the Yamcs script evaluation engine for Python algorithms dynamically compiled and evaluated user-controlled algorithm text using Jython through the JSR-223 ScriptEngine API without enforcing a secure sandbox, so an authenticated user with the ChangeMissionDatabase privilege could override an existing Python algorithm's logic through the mission database REST API and import and execute arbitrary Java classes such as java.lang.Runtime to achieve remote code execution on the underlying host operating system. This issue is fixed in versions 5.12.7 and 5.13.0, which disable algorithm editing by default.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Spaceapplications ≫ Yamcs Version < 5.12.7
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 1% | 0.591 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| security-advisories@github.com | 9.1 | 2.3 | 6 |
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
|
CWE-94 Improper Control of Generation of Code ('Code Injection')
The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.
https://github.com/yamcs/yamcs/releases/tag/yamcs-5.12.7
https://github.com/yamcs/yamcs/releases/tag/yamcs-5.13.0
https://github.com/yamcs/yamcs/commit/3c550348f866af4675d2ba4a51d8d12b7c7c6011
https://github.com/yamcs/yamcs/commit/4ff8fda642ea8c3309a4d3f379aa77b763148992
https://github.com/yamcs/yamcs/security/advisories/GHSA-2g95-6x5q-xjwj