CVE-2024-39780 - CVE House
Back to Database
Status published High CVE-2024-39780

Use of unsafe yaml load in dynparam

Vulnerability Description

A YAML deserialization vulnerability was found in the Robot Operating System (ROS) 'dynparam', a command-line tool for getting, setting, and deleting parameters of a dynamically configurable node, affecting ROS distributions Noetic and earlier. The issue is caused by the use of the yaml.load() function in the 'set' and 'get' verbs, and allows for the creation of arbitrary Python objects. Through this flaw, a local or remote user can craft and execute arbitrary Python code.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-39780

Credits & Attribution

The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:

  • Florencia Cabral Berenfus, Ubuntu Robotics Team

Affected Vendor

Open Source Robotics Foundation

View all reports →

Affected Software

Robot Operating System (ROS)
Vulnerable Versions:
Noetic Ninjemys, Melodic Morenia, Kinetic Kame, Indigo Igloo

Timeline

Official Publish: April 2nd, 2025
Last Modified: June 18th, 2025
Added to House: July 22nd, 2026

CVSS Vectors

V3: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Weaknesses (CWE)