Vulnerabilities & Exploits · Web App Attack

ROS# File Server Can Rewrite Its Own Files

ROS# file_server is not just a URDF transfer tool. In versions before 2.2.2, a path traversal flaw lets a remote attacker read and write arbitrary files that the service account can access, and that blast radius grows fast if the service runs with broader host privileges.

Siemens says ROS# versions before 2.2.2 are affected and has released v2.2.2 as the fix. The advisory calls out read and write access to files on the host through the file_server service, with impact bounded by the rights of the account running it.

The risk is conditional, not universal. A tightly scoped service account limits the damage, but an elevated one can turn file access into startup tampering, secret theft, or persistence on the host.

1 source · May 14

CVE-2026-41551

NVD KEV

CVSS 9.1 CRITICAL: a vulnerability has been identified in ROS# (All versions < V2.2.2). EPSS 0.5% (38th percentile).

Timeline

Sources

Part of the PlainSec briefing for 2026-05-15

Every edition of this story: ROS# File Server Can Rewrite Its Own Files

More from today