{"id":"CVE-2026-55565","title":"Yamcs is a mission control framework","summary":"Yamcs is a mission control framework. Prior to 5.12.8 and 5.13.2, Yamcs LikeExpression.fillCode_getValueReturn in yamcs-core/src/main/java/org/yamcs/yarch/streamsql/LikeExpression.java inserts an unescaped LIKE pattern into Java source c…","severity":"critical","cvss":9.9,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H","cwe":["CWE-94"],"vendor":"yamcs","product":"org.yamcs:yamcs-core","affected":["org.yamcs:yamcs-core >= 5.13.0, <= 5.13.1","org.yamcs:yamcs-core <= 5.12.7"],"patched":["org.yamcs:yamcs-core 5.13.2","org.yamcs:yamcs-core 5.12.8"],"published":"2026-08-28","updated":"2026-09-08","sourceUpdated":"2026-09-08T21:08:37.320","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-55565","references":[{"url":"https://github.com/yamcs/yamcs/commit/640e1598b7097b521692e89dd47a39b6cb1fc663","label":"security-advisories@github.com"},{"url":"https://github.com/yamcs/yamcs/commit/a8fb4a0693fa62a6eb729b26016d1090dd8b289c","label":"security-advisories@github.com"},{"url":"https://github.com/yamcs/yamcs/releases/tag/yamcs-5.12.8","label":"security-advisories@github.com"},{"url":"https://github.com/yamcs/yamcs/releases/tag/yamcs-5.13.2","label":"security-advisories@github.com"},{"url":"https://github.com/yamcs/yamcs/security/advisories/GHSA-c64q-hj4j-375f","label":"security-advisories@github.com"},{"url":"https://github.com/yamcs/yamcs/security/advisories/GHSA-c64q-hj4j-375f","label":"134c704f-9b21-4f2e-91b3-4a467353bcc0"},{"url":"https://github.com/advisories/GHSA-c64q-hj4j-375f"}],"tags":["nvd","ghsa","maven"],"epss":0.00457,"epssPercentile":0.38995,"aliases":["GHSA-c64q-hj4j-375f"],"ecosystem":"maven","ingestedAt":"2026-08-28T18:23:37.964Z","slug":"CVE-2026-55565","body":"## Overview\n\nYamcs is a mission control framework. Prior to 5.12.8 and 5.13.2, Yamcs LikeExpression.fillCode_getValueReturn in yamcs-core/src/main/java/org/yamcs/yarch/streamsql/LikeExpression.java inserts an unescaped LIKE pattern into Java source compiled by Expression.getCompiledExpression through SimpleCompiler.cook instead of applying ValueExpression.escapeJavaString. The pattern can originate from POST /api/archive/{instance}:executeSql, POST /api/archive/{instance}:streamSql, POST /api/archive/{instance}/tables/{table}:readRows, GET /api/archive/{instance}/events, or activity searches, including paths available with ReadTables, ReadEvents, or ReadActivities. A quote in the pattern can inject Java that runs as the Yamcs server process. This issue is fixed in versions 5.12.8 and 5.13.2.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.\n\n## Package advisory (CVE-2026-55565)\n\nAffected packages:\n\n- `org.yamcs:yamcs-core >= 5.13.0, <= 5.13.1`\n- `org.yamcs:yamcs-core <= 5.12.7`\n\nPatched in:\n\n- `org.yamcs:yamcs-core 5.13.2`\n- `org.yamcs:yamcs-core 5.12.8`\n\nSource: https://github.com/advisories/GHSA-c64q-hj4j-375f","depth":"midnight","depthScore":55,"depthScoreParts":{"impact":54.5,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}