THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-73mf-m39p-wpm9 (critical) — Yamcs vulnerable to Remote Code Execution via instance-template argument YAML injection (createInstance)

[GHSA] GHSA-73mf-m39p-wpm9 (critical) — Yamcs vulnerable to Remote Code Execution via instance-template argument YAML injection (createInstance)

medgithub_advisoriesPublished 2026-08-28

GHSA-73mf-m39p-wpm9 Severity: critical CVE: CVE-2026-55559

Yamcs vulnerable to Remote Code Execution via instance-template argument YAML injection (createInstance)

### Summary

`templateArgs` sent to `POST /api/instances` (and `PATCH /api/instances/{instance}`) are written into the rendered instance config as raw text, then parsed as YAML and loaded. Yamcs instantiates each `services:` entry by

Indicators of compromise

Original source: https://github.com/advisories/GHSA-73mf-m39p-wpm9