top of page
perceptive_background_267k.jpg

Yamcs is a mission control framework. Prior to 5.12.8 and 5.13.2, Yamcs LikeExpression.fillCode_getValueReturn in yamcs-core/src/main/java/org/yamcs/yarch/strea…

Published:

28 August 2026 at 00:00:00

Alert date:

28 August 2026 at 23:18:32

Source:

nvd.nist.gov

Click to open the original link from this advisory

Critical Infrastructure, Enterprise Applications, Web Technologies

A code injection vulnerability exists in Yamcs, a mission control framework, prior to versions 5.12.8 and 5.13.2. The flaw resides in LikeExpression.fillCode_getValueReturn in LikeExpression.java, where an unescaped LIKE pattern is inserted into Java source code compiled at runtime via SimpleCompiler.cook, bypassing the escapeJavaString sanitization. The vulnerability can be triggered through multiple API endpoints including executeSql, streamSql, readRows, events, and activity searches. Attackers with access to these endpoints (ReadTables, ReadEvents, or ReadActivities permissions) can inject arbitrary Java code that executes with the privileges of the Yamcs server process. This represents a serious remote code execution risk in mission-critical environments. The issue has been patched in Yamcs versions 5.12.8 and 5.13.2, with fixes available via two separate commits on GitHub.

Technical details

Mitigation steps:

Affected products:

Yamcs

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Disclaimer: Deze website toont informatie afkomstig van externe bronnen. Perceptive aanvaardt geen verantwoordelijkheid voor de inhoud, juistheid of volledigheid van deze informatie.

bottom of page