Impact
The vulnerability lies in the EGOReplanFSM::checkCollisionCallback method of the EGO‑Planner‑v2 codebase. A crafted input causes a crash inside the collision callback, leading to an abrupt termination of the planner process. Because the planner drives vehicle motion, the crash results in a denial‑of‑service that can render the autonomous system inoperable. The weakness matches CWE‑400, an improper termination or resource termination scenario.
Affected Systems
The issue affects all releases of ZJU‑FAST‑Lab EGO‑Planner‑v2 up to commit 5c99a95880401e2599638d567abc0e240396cb42. Users running any of those versions are vulnerable until they upgrade to a revision newer than that commit. No other vendor or product is currently known to be impacted.
Risk and Exploitability
EPSS score is less than 1%, indicating a very low probability of exploitation. The vulnerability is not listed in CISA’s KEV catalog, suggesting no documented widespread exploitation. Based on the description, the attack vector is likely an externally supplied input to the planner’s collision callback, which could be transmitted over a local network or API exposed by the vehicle. If an attacker can provide malformed data, the planner will crash, causing a service disruption. While exploitation remains uncertain, a successful denial of service would have a high impact.
OpenCVE Enrichment