ROS# file_server is not just a URDF transfer tool. In versions before 2.2.2, a path traversal flaw lets a remote attacker read and write arbitrary files that the service account can access, and that blast radius grows fast if the service runs with broader host privileges.
Siemens says ROS# versions before 2.2.2 are affected and has released v2.2.2 as the fix. The advisory calls out read and write access to files on the host through the file_server service, with impact bounded by the rights of the account running it.
The risk is conditional, not universal. A tightly scoped service account limits the damage, but an elevated one can turn file access into startup tampering, secret theft, or persistence on the host.