top of page
perceptive_background_267k.jpg

Yamcs is a mission control framework. Prior to 5.12.8 and 5.13.2, Yamcs inserts templateArgs from POST /api/instances and PATCH /api/instances/{instance} into Y…

Published:

28 augustus 2026 om 00:00:00

Alert date:

28 augustus 2026 om 23:18:31

Source:

nvd.nist.gov

Click to open the original link from this advisory

Critical Infrastructure, Web Technologies, Enterprise Applications

A YAML injection vulnerability exists in Yamcs mission control framework prior to versions 5.12.8 and 5.13.2. The flaw resides in VarStatement.append, which inserts templateArgs from POST/PATCH API endpoints into YAML configuration without proper escaping. An attacker can inject a malicious services entry for org.yamcs.ProcessRunner into the rendered configuration, leading to arbitrary command execution as the Yamcs service account. Unsecured deployments lacking security.yaml are exposed via the guest superuser, making exploitation trivially accessible. Secured deployments require the SystemPrivilege.CreateInstances privilege to exploit. The vulnerability affects the instance management API endpoints and the underlying YAML templating engine. Fixes are available in Yamcs versions 5.12.8 and 5.13.2. Organizations running Yamcs in mission-critical or space/aerospace environments should prioritize patching immediately.

Technical details

Mitigation steps:

Affected products:

Yamcs mission control framework (prior to 5.12.8 and 5.13.2)

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page