Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
8.4

CVE-2026-58459: gpsd gpsprof Command Injection via gnuplot plot title

CVE-2026-58459 CVE-2026-58459
Summary

A security flaw in gpsd's gpsprof feature allows attackers to execute arbitrary commands on the system by manipulating the GPS device subtype value. This could potentially allow an attacker to take control of the system or access sensitive data. To fix this issue, update gpsd to a version that has been patched for this vulnerability.

What to do

No fix is available yet. Check with your software vendor for updates.

Affected software
VendorProductAffected versions
ntpsec gpsd <= 3.27.5
gpsd_project gpsd <= 3.27.5
cpe:2.3:a:gpsd_project:gpsd:*:*:*:*:*:*:*:*
Original title
gpsd through release-3.27.5, fixed at commit 4c06658, contains a command injection vulnerability in gpsprof that allows attackers who control the GPS device subtype value to execute arbitrary shell...
Original description
gpsd through release-3.27.5, fixed at commit 4c06658, contains a command injection vulnerability in gpsprof that allows attackers who control the GPS device subtype value to execute arbitrary shell commands by embedding backtick payloads in the gnuplot plot title without proper escaping. The subtype field sourced from a DEVICES JSON log entry or NMEA PGRMT sentence is written into a generated gnuplot program via a set title statement with only double-quote characters escaped, enabling arbitrary shell command execution as the user running gnuplot when the victim renders the generated plot through the gpsprof and gnuplot workflow.
nvd CVSS3.1 7.8
nvd CVSS4.0 8.4
Vulnerability type
CWE-78 OS Command Injection
Published: 9 Jul 2026 · Updated: 18 Jul 2026 · First seen: 9 Jul 2026