Yamcs is a mission control framework. Prior to 5.12.7, the Yamcs script evaluation engine for Python algorithms dynamically compiled and evaluated user-controlled algorithm text using Jython through the JSR-223 ScriptEngine API without enforcing a secure sandbox, so an authenticated user with the ChangeMissionDatabase privilege could override an existing Python algorithm's logic through the mission database REST API and import and execute arbitrary Java classes such as java.lang.Runtime to achieve remote code execution on the underlying host operating system. This issue is fixed in versions 5.12.7 and 5.13.0, which disable algorithm editing by default.
References
| Link | Resource |
|---|---|
| https://github.com/yamcs/yamcs/commit/3c550348f866af4675d2ba4a51d8d12b7c7c6011 | Patch |
| https://github.com/yamcs/yamcs/commit/4ff8fda642ea8c3309a4d3f379aa77b763148992 | Patch |
| https://github.com/yamcs/yamcs/releases/tag/yamcs-5.12.7 | Release Notes |
| https://github.com/yamcs/yamcs/releases/tag/yamcs-5.13.0 | Release Notes |
| https://github.com/yamcs/yamcs/security/advisories/GHSA-2g95-6x5q-xjwj | Exploit Vendor Advisory |
| https://github.com/yamcs/yamcs/security/advisories/GHSA-2g95-6x5q-xjwj | Exploit Vendor Advisory |
Configurations
History
20 Jul 2026, 01:46
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://github.com/yamcs/yamcs/commit/3c550348f866af4675d2ba4a51d8d12b7c7c6011 - Patch | |
| References | () https://github.com/yamcs/yamcs/commit/4ff8fda642ea8c3309a4d3f379aa77b763148992 - Patch | |
| References | () https://github.com/yamcs/yamcs/releases/tag/yamcs-5.12.7 - Release Notes | |
| References | () https://github.com/yamcs/yamcs/releases/tag/yamcs-5.13.0 - Release Notes | |
| References | () https://github.com/yamcs/yamcs/security/advisories/GHSA-2g95-6x5q-xjwj - Exploit, Vendor Advisory | |
| CPE | cpe:2.3:a:spaceapplications:yamcs:*:*:*:*:*:*:*:* | |
| First Time |
Spaceapplications
Spaceapplications yamcs |
16 Jul 2026, 19:16
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://github.com/yamcs/yamcs/security/advisories/GHSA-2g95-6x5q-xjwj - |
16 Jul 2026, 17:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-07-16 17:16
Updated : 2026-07-20 01:46
NVD link : CVE-2026-46621
Mitre link : CVE-2026-46621
CVE.ORG link : CVE-2026-46621
JSON object : View
Products Affected
spaceapplications
- yamcs
CWE
CWE-94
Improper Control of Generation of Code ('Code Injection')
