CVE-2026-71640
ZJU-FAST-Lab · EGO-Planner-v2
A vulnerability in ZJU-FAST-Lab EGO-Planner-v2 allows for unsafe vehicle motion by failing to properly handle expired trajectory data within the replanning pipeline.
Executive summary
A critical vulnerability in the EGO-Planner-v2 motion planning software allows an unauthenticated attacker to trigger unsafe vehicle behavior, posing a severe risk to physical system integrity.
Vulnerability
The flaw resides in the replanning pipeline, where improper handling of expired trajectory data can be leveraged by an unauthenticated attacker to induce unsafe motion commands in the vehicle.
Business impact
The exploitation of this vulnerability carries extreme safety and operational risks, as it can directly influence the physical movement of autonomous vehicles. Given the CVSS score of 9.1, this is classified as critical, representing a high potential for physical damage, loss of control, and significant safety hazards in real-world deployment environments.
Remediation
Immediate Action: Organizations using EGO-Planner-v2 should review the repository for official updates or patches addressing the trajectory handling logic and restrict network access to the replanning interface.
Proactive Monitoring: Monitor system logs for anomalous trajectory calculation requests or unexpected replanning events that deviate from established operational parameters.
Compensating Controls: Implement network-level access controls to ensure that the replanning service is not exposed to untrusted or public networks, effectively isolating the component from remote exploitation attempts.
Exploitation status
Public Exploit Available: Unknown.
Analyst recommendation
Given the critical nature of this flaw and its direct impact on physical vehicle motion, it is imperative to treat this as a high-priority incident. Administrators must audit current deployments of EGO-Planner-v2 and apply the latest available updates from the vendor immediately to mitigate the risk of unauthorized trajectory manipulation.
History
CVE Brief tracked this CVE 5 days before it had a CVSS score.
- Disclosed CVE record published
- Collected by CVE Brief No CVSS score yet; tracked as early warning
- CVSS score assigned 9.1 (3.1)
- Analyst report written