HIGH

CVE-2026-60122

CVSS v3

7.8

HIGH

EPSS Score

0.2%

exploit probability

CISA KEV

No

known exploited

Exploitation

SSVC status

Description

gpsd through release-3.27.5, fixed at commit 4c06658, contains a code injection vulnerability in the gpsprof utility that allows an attacker who controls GPS input data to execute arbitrary OS commands by injecting malicious content into the SKY.satellites[].used field, which is inserted unsanitized into a gnuplot heredoc data block. Attackers can supply a used value containing the string EOD to terminate the heredoc early and append gnuplot system() calls, achieving OS command execution as the

Technical details

CVSS v3 Vector
3.1
Published
7/23/2026
Last Modified
7/23/2026

Frequently asked questions

What is CVE-2026-60122?

gpsd through release-3.27.5, fixed at commit 4c06658, contains a code injection vulnerability in the gpsprof utility that allows an attacker who controls GPS input data to execute arbitrary OS commands by injecting malicious content into the SKY.satellites[].used field, which is inserted unsanitized into a gnuplot heredoc data block. Attackers can supply a used value containing the string EOD to terminate the heredoc early and append gnuplot system() calls, achieving OS command execution as the

Is CVE-2026-60122 actively exploited?

Active exploitation of CVE-2026-60122 has not been confirmed. The EPSS score is 0.2%, indicating the estimated probability of exploitation in the next 30 days.

What is the CVSS score for CVE-2026-60122?

CVE-2026-60122 has a CVSS v3 base score of 7.8 (HIGH severity), with vector string 3.1.

Is CVE-2026-60122 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.