OS Command Injection Affecting gpsd package, versions <3.27.5-1


Severity

Recommended
0.0
critical
0
10

Snyk's Security Team recommends NVD's CVSS assessment. Learn more

Threat Intelligence

EPSS
1.8% (77th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-DEBIANUNSTABLE-GPSD-17933188
  • published10 Jul 2026
  • disclosed9 Jul 2026

Introduced: 9 Jul 2026

CVE-2026-58459  (opens in a new tab)
CWE-78  (opens in a new tab)

How to fix?

Upgrade Debian:unstable gpsd to version 3.27.5-1 or higher.

NVD Description

Note: Versions mentioned in the description apply only to the upstream gpsd package and not the gpsd package as distributed by Debian. See How to fix? for Debian:unstable relevant fixed versions and status.

gpsd through release-3.27.5, fixed at commit 4c06658, contains a command injection vulnerability in gpsprof that allows attackers who control the GPS device subtype value to execute arbitrary shell commands by embedding backtick payloads in the gnuplot plot title without proper escaping. The subtype field sourced from a DEVICES JSON log entry or NMEA PGRMT sentence is written into a generated gnuplot program via a set title statement with only double-quote characters escaped, enabling arbitrary shell command execution as the user running gnuplot when the victim renders the generated plot through the gpsprof and gnuplot workflow.

CVSS Base Scores

version 3.1