Vendor
high
advisory
GPSD Code Injection Vulnerability in gpsprof (CVE-2026-60122)
1 rule 1 TTP 1 CVEA high-severity code injection vulnerability, CVE-2026-60122, exists in the gpsprof utility of gpsd through version 3.27.5, allowing an attacker to achieve arbitrary OS command execution by injecting malicious content into GPS input data processed by gnuplot.
gpsd
code-injection
command-injection
gnuplot
linux
macos
privilege-escalation
1r
1t
1c
high
advisory
CVE-2026-58459 - gpsd gpsprof Command Injection
2 rules 1 TTP 1 CVEA command injection vulnerability, CVE-2026-58459, exists in the gpsprof utility of gpsd through version 3.27.5, allowing an attacker to exploit this by controlling the GPS device subtype value and embedding backtick payloads within the gnuplot plot title, which leads to arbitrary shell command execution as the user running gnuplot when a victim renders a generated plot via the gpsprof and gnuplot workflow due to improper escaping.
gpsd
command-injection
vulnerability
execution
linux
macos
2r
1t
1c