THREAT OPS › Threat News › [GHSA] GHSA-73mf-m39p-wpm9 (critical) — Yamcs vulnerable to Remote Code Execution via instance-template argument YAML injection (createInstance)
[GHSA] GHSA-73mf-m39p-wpm9 (critical) — Yamcs vulnerable to Remote Code Execution via instance-template argument YAML injection (createInstance)
GHSA-73mf-m39p-wpm9 Severity: critical CVE: CVE-2026-55559
Yamcs vulnerable to Remote Code Execution via instance-template argument YAML injection (createInstance)
### Summary
`templateArgs` sent to `POST /api/instances` (and `PATCH /api/instances/{instance}`) are written into the rendered instance config as raw text, then parsed as YAML and loaded. Yamcs instantiates each `services:` entry by
Indicators of compromise
- CVE-2026-55559cve
- CVE-2026-46562cve
Original source: https://github.com/advisories/GHSA-73mf-m39p-wpm9