Description
An issue in ZJU-FAST-Lab EGO-Planner-v2 All versions up to commit 5c99a95880401e2599638d567abc0e240396cb42 allows unsafe vehicle motion via improper handling of expired trajectory data in the replanning pipeline
Published: 2026-09-10
Score: 9.1 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Unsafe vehicle motion due to improper handling of expired trajectory data
Action: Immediate Mitigation
AI Analysis

Impact

An issue in EGO‑Planner‑ replanning pipeline processes trajectory data that has already expired. The flaw means that outdated commands can be executed as if they were still valid, potentially causing the vehicle to follow an incorrect path, collide with obstacles, or otherwise behave unpredictably. The vulnerability is a logic flaw where the system does not verify the freshness of trajectory inputs before acting upon them.

Affected Systems

All released versions of ZJU‑FAST‑Lab EGO‑Planner‑v2 up to commit 5c99a95880401e2599638d567abc0e240396cb42 are affected. No vendor or product names are listed beyond the repository name, commit hash.

Risk and Exploitability

The EPSS score is <1%, indicating a very low probability of exploitation in the real world. The vulnerability is not listed in the CISA KEV catalog, so the publicly observable exploitation probability is unclear. The likely attack vector is through input that contains stale trajectory data; an attacker could craft or manipulate sensor feeds or plan inputs that the system will treat as current, thereby inducing unsafe motion. Because the flaw is a logic error in handling timing, any system that accepts external trajectory data without strict freshness validation could be at risk. The severity is therefore considered high, with a CVSS score of 9.1, especially in safety‑critical vehicle operations where inadvertent motion can lead to severe accidents.

Generated by OpenCVE AI on September 21, 2026 at 05:23 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest patch or upgrade to a version of EGO‑Planner‑v2 that removes the data at the point of insertion: reject any command whose timestamp be accepted for execution.
  • Introduce runtime checks that flag or discard expired trajectories and restore the vehicle to a safe state if such data is detected.
  • Add monitoring for anomalous motion or timing irregularities in the replanning loop to detect potential misuse of stale data.

Generated by OpenCVE AI on September 21, 2026 at 05:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 21 Sep 2026 05:45:00 +0000

Type Values Removed Values Added
Title Unsafe Vehicle Motion Due to Expired Trajectory Data Handling in EGO‑Planner‑v2

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-703
Metrics cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sun, 13 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Zju-fast-lab
Zju-fast-lab ego-planner-v2
Vendors & Products Zju-fast-lab
Zju-fast-lab ego-planner-v2

Fri, 11 Sep 2026 06:45:00 +0000

Type Values Removed Values Added
Title Unsafe Vehicle Motion Due to Expired Trajectory Data Handling in EGO‑Planner‑v2

Fri, 11 Sep 2026 05:30:00 +0000

Type Values Removed Values Added
Title Unsafe Vehicle Motion via Expired Trajectory Data in EGO‑Planner‑v2
Weaknesses CWE-368

Fri, 11 Sep 2026 01:45:00 +0000

Type Values Removed Values Added
Title Unsafe Vehicle Motion via Expired Trajectory Data in EGO‑Planner‑v2
Weaknesses CWE-368

Thu, 10 Sep 2026 22:00:00 +0000

Type Values Removed Values Added
Description An issue in ZJU-FAST-Lab EGO-Planner-v2 All versions up to commit 5c99a95880401e2599638d567abc0e240396cb42 allows unsafe vehicle motion via improper handling of expired trajectory data in the replanning pipeline
References

Subscriptions

Zju-fast-lab Ego-planner-v2
cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-09-14T16:09:38.547Z

Reserved: 2026-08-07T00:00:00.000Z

Link: CVE-2026-71640

cve-icon Vulnrichment

Updated: 2026-09-14T16:08:53.111Z

cve-icon NVD

Status : Deferred

Published: 2026-09-10T22:16:58.643

Modified: 2026-09-22T20:00:03.713

Link: CVE-2026-71640

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T05:30:07Z

Weaknesses
  • CWE-703

    Improper Check or Handling of Exceptional Conditions