Executive brief
A vulnerability exists in gpsd, a service used to manage GPS and other location sensors. The 'gpsprof' tool, which generates visual plots of GPS data, fails to properly clean device information before passing it to the gnuplot graphing software. If a user is tricked into processing a malicious GPS log or connecting to a compromised GPS device, an attacker could execute arbitrary commands on the user's computer, potentially leading to full system compromise or data theft.
Technical details
A command injection vulnerability exists in the gpsprof utility within gpsd through release 3.27.5. The root cause is the improper neutralization of special elements in the 'subtype' field, which is sourced from DEVICES JSON log entries or NMEA PGRMT sentences. When gpsprof generates a gnuplot script, it embeds this subtype into a 'set title' statement, escaping only double-quote characters but failing to escape backticks used for command substitution. An attacker can provide a crafted subtype containing backtick payloads (e.g., `id`) that execute arbitrary shell commands in the context of the user running gnuplot. The vulnerability was addressed in commit 4c06658 by implementing proper escaping for backticks and other special characters.
Affected products
- ntpsec gpsd through 3.27.5
Timeline
- 2026-06-27: disclosed: Vulnerability reported to vendor by VulnCheck
- 2026-07-09: advisory: NVD and VulnCheck advisory published
- 2026-07-09: patched: Fix confirmed in commit 4c06658
References
- https://github.com/ntpsec/gpsd/commit/1a6bb7bcbdf58aa940132e630870af061dc88537
- https://github.com/ntpsec/gpsd/commit/4c06658e988f4ced1a7a574ce082a22ef625df56
- https://github.com/ntpsec/gpsd/commit/5581ba196d826a984fbfaf792b7d58535f9911ce
- https://gitlab.com/gpsd/gpsd/-/work_items/404
- https://www.vulncheck.com/advisories/gpsd-gpsprof-command-injection-via-gnuplot-plot-title-subtype-field