THREAT OPS › Threat News › [GHSA] GHSA-c64q-hj4j-375f (critical) — Yamcs vulnerable to authenticated remote code execution via unescaped StreamSQL `LIKE` pattern compiled by Janino (`LikeExpression`)
[GHSA] GHSA-c64q-hj4j-375f (critical) — Yamcs vulnerable to authenticated remote code execution via unescaped StreamSQL `LIKE` pattern compiled by Janino (`LikeExpression`)
GHSA-c64q-hj4j-375f Severity: critical CVE: CVE-2026-55565
Yamcs vulnerable to authenticated remote code execution via unescaped StreamSQL `LIKE` pattern compiled by Janino (`LikeExpression`)
## Summary Yamcs compiles StreamSQL query expressions to Java at runtime with Janino. The `LIKE` operator inserts the user-supplied pattern into the generated Java **unescaped**, inside a `"..."` literal, s
Indicators of compromise
- CVE-2026-55565cve
- CVE-2026-46562cve
Original source: https://github.com/advisories/GHSA-c64q-hj4j-375f