Impact
An issue in EGO‑Planner‑v2 allows unsafe vehicle motion when the replanning pipeline processes trajectory data that has already expired. The flaw means that outdated commands can be executed as if they were still valid, potentially causing the vehicle to follow an incorrect path, collide with obstacles, or otherwise behave unpredictably. The vulnerability is a logic flaw where the system does not verify the freshness of trajectory inputs before acting upon them.
Affected Systems
All released versions of ZJU‑FAST‑Lab EGO‑Planner‑v2 up to commit 5c99a95880401e2599638d567abc0e240396cb42 are affected. No vendor or product names are listed beyond the repository name, and no specific version ranges are provided beyond the commit hash.
Risk and Exploitability
The EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog, so the publicly observable exploitation probability is unclear. The likely attack vector is through input that contains stale trajectory data; an attacker could craft or manipulate sensor feeds or plan inputs that the system will treat as current, thereby inducing unsafe motion. Because the flaw is a logic error in handling timing, any system that accepts external trajectory data without strict freshness validation could be at risk. The severity is therefore considered high, especially in safety‑critical vehicle operations where inadvertent motion can lead to severe accidents.
OpenCVE Enrichment