Junglewise Threat Intelligence

CVE-2025-56814: OpenCPN Launcher Plugin command injection in wxExecute

CVE-2025-56814 · Severity: info · Published 2026-06-15

Executive brief

OpenCPN is a popular open-source navigation software used by sailors and mariners to display electronic charts. A security flaw in its Launcher Plugin allows for the execution of unauthorized system commands when processing user-defined shortcuts. If an attacker can influence these command strings, they could gain full control over the computer running the navigation software, potentially leading to data theft or system disruption.

Technical details

A command injection vulnerability exists in the Launcher Plugin (launcher_pi.cpp) of OpenCPN v5.12.0. The issue resides in the LauncherUIDialog::OnBtnClick function, where user-defined commands are retrieved and processed. The application performs string replacements for navigation variables (like latitude and longitude) but fails to sanitize the resulting string before passing it to wxExecute(cmd, wxEXEC_ASYNC). Because the command is executed via the system shell without proper filtering, an attacker can inject shell metacharacters such as ampersands (&) or pipes (|) to execute arbitrary system commands. This vulnerability primarily affects Windows environments where the plugin is active.

Affected products

  • OpenCPN OpenCPN Launcher Plugin v1.3.5 (OpenCPN v5.12.0)

Timeline

  • 2025-07-14: other: Vulnerability research period began
  • 2026-06-15: disclosed: CVE published to NVD

References