CVE Feed

    Dashboard / CVE / CVE-2026-58459

    CVE-2026-58459

    gpsd through release-3.27.5, fixed at commit 4c06658, contains a command injection vulnerability in gpsprof that allows attackers who control the GPS device subtype value to execute arbitrary shell commands by embedding backtick payloads in the gnuplot plot title without proper escaping. The subtype field sourced from a DEVICES JSON log entry or NMEA PGRMT sentence is written into a generated gnuplot program via a set title statement with only double-quote characters escaped, enabling arbitrary shell command execution as the user running gnuplot when the victim renders the generated plot through the gpsprof and gnuplot workflow.

    Published:Jul 9, 2026
    Last Modified:Jul 28, 2026
    EPS:Jul 9, 2026
    EPSS Score:0.01796
    CVSS Score:7.8

    Affected Products

    Vendor
    Gpsd Project
    Product
    Gpsd
    Vendor
    Ntpsec
    Product
    Gpsd

    Related CVEs

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High