CVE-2026-58459

Name
CVE-2026-58459
Description
gpsd through release-3.27.5, fixed at commit 4c06658, contains a command injection vulnerability in gpsprof that allows attackers who control the GPS device subtype value to execute arbitrary shell commands by embedding backtick payloads in the gnuplot plot title without proper escaping. The subtype field sourced from a DEVICES JSON log entry or NMEA PGRMT sentence is written into a generated gnuplot program via a set title statement with only double-quote characters escaped, enabling arbitrary shell command execution as the user running gnuplot when the victim renders the generated plot through the gpsprof and gnuplot workflow.
NVD Severity
unknown
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
disclosure@vulncheck.com https://github.com/ntpsec/gpsd/commit/1a6bb7bcbdf58aa940132e630870af061dc88537
disclosure@vulncheck.com https://github.com/ntpsec/gpsd/commit/4c06658e988f4ced1a7a574ce082a22ef625df56
disclosure@vulncheck.com https://github.com/ntpsec/gpsd/commit/5581ba196d826a984fbfaf792b7d58535f9911ce
disclosure@vulncheck.com https://gitlab.com/gpsd/gpsd/-/work_items/404#note_3534119267
disclosure@vulncheck.com https://www.vulncheck.com/advisories/gpsd-gpsprof-command-injection-via-gnuplot-plot-title-subtype-field

Match rules

CPE URI Source package Min version Max version
cpe:2.3:a:gpsd_project:gpsd:*:*:*:*:*:*:*:* gpsd >= None <= 3.27.5

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
gpsd edge-main 3.27.3-r1 Nathan Angelacos <nangel@alpinelinux.org> possibly vulnerable
gpsd edge-main 3.27.3-r0 Nathan Angelacos <nangel@alpinelinux.org> possibly vulnerable
gpsd edge-main 3.26.1-r0 Nathan Angelacos <nangel@alpinelinux.org> possibly vulnerable
gpsd edge-main 3.25-r3 Nathan Angelacos <nangel@alpinelinux.org> possibly vulnerable
gpsd edge-main 3.25-r2 Nathan Angelacos <nangel@alpinelinux.org> possibly vulnerable
gpsd 3.24-main 3.27.3-r1 Nathan Angelacos <nangel@alpinelinux.org> possibly vulnerable
gpsd 3.23-main 3.26.1-r0 Nathan Angelacos <nangel@alpinelinux.org> possibly vulnerable
gpsd 3.22-main 3.26.1-r0 Nathan Angelacos <nangel@alpinelinux.org> possibly vulnerable
gpsd 3.21-main 3.25-r2 Nathan Angelacos <nangel@alpinelinux.org> possibly vulnerable
gpsd 3.20-main 3.25-r2 Nathan Angelacos <nangel@alpinelinux.org> possibly vulnerable
gpsd 3.19-main 3.25-r1 Nathan Angelacos <nangel@alpinelinux.org> possibly vulnerable