By vendor
Gpsd_project vulnerabilities
Known CVEs affecting Gpsd_project products, prioritized by severity, with SEC.co remediation and detection guidance.
1 published vulnerability
- CVE-2026-58459HIGH 7.8
A vulnerability in gpsd (the open-source GPS daemon) allows attackers to run arbitrary shell commands on systems running gpsprof if an attacker can control the GPS device subtype information. The flaw exists because subtype values from GPS data aren't properly sanitized before being inserted into gnuplot commands. When a user generates a plot using gpsprof and gnuplot, the malicious subtype text (containing backticks or shell metacharacters) gets executed as shell commands by the user running gnuplot. This is a local-attack scenario requiring either direct control of a GPS device or manipulation of GPS log data.