External risk intelligence

EGO-Planner-v2 Unsafe Vehicle Motion from Expired Trajectory Data

CVE advisorySeverity: CRITICAL (CVSS 9.1)

CVE-2026-71640

This software is a robotics motion planning library (EGO-Planner) intended for drone or vehicle navigation. It is designed for internal control systems and local onboard processing rather than internet-facing services, web applications, or remote gateway roles.

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This vulnerability involves an issue in a robotics motion planning library that could lead to unsafe vehicle movement if expired trajectory data is not handled correctly. The potential impact is a critical risk, affecting the integrity and availability of systems using this software for navigation. The main concern is confirming relevance and exposure within your specific operational technology environments.

  • Unsafe motion control in planning software.
  • Critical risk to system integrity and availability.
  • Confirm relevance and exposure in operational technology.

Attack Path

How an attacker could exploit the issue

An attacker could reach this vulnerability through network access, interacting with a system running the EGO-Planner-v2 motion planning library. By sending specifically crafted, expired trajectory data, an attacker could cause the system to improperly handle this information within its replanning pipeline. This mishandling could lead to unsafe vehicle motion.

  • Network access required.
  • Expired trajectory data sent.
  • Unsafe vehicle motion possible.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability could allow an attacker to cause unsafe vehicle motion through improper handling of expired trajectory data within the replanning pipeline. This could occur when the system attempts to replan a vehicle's path using outdated information, potentially leading to unexpected movements.

  • Vehicle trajectory data is at risk.
  • Unsafe motion may occur with expired data.
  • Loss of vehicle control is a potential consequence.

Operational Fix

Recommended remediation, mitigation, and detection steps

The EGO-Planner-v2 is a robotics motion planning library, likely deployed within internal control systems for autonomous vehicles or drones. Responsibility for addressing this issue will fall to the teams managing these systems, potentially including robotics engineers, platform owners, or embedded systems developers. The first practical step is to identify all instances of EGO-Planner-v2, determine their operational criticality and network exposure, and then assign ownership for remediation planning based on that risk assessment.

  • Identify affected systems and owners.
  • Verify exposure and criticality.
  • Plan targeted remediation or mitigation.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is EGO-Planner-v2?

EGO-Planner-v2 is an open-source robotics motion planning library developed by ZJU-FAST-Lab. It is primarily used by researchers and engineers to enable autonomous navigation for drones and ground vehicles. The software calculates optimal, collision-free paths in real-time, allowing mobile robots to move safely through complex environments by processing sensor data and generating motion trajectories on the fly.

How does CVE-2026-71640 create unsafe vehicle motion?

This vulnerability is classified under CWE-703, which relates to improper handling of exceptional conditions. In this specific case, the software fails to correctly validate the freshness of trajectory data. Because the replanning pipeline does not properly discard or ignore outdated information, the system may base its navigation decisions on expired data, resulting in erroneous or unsafe physical movements of the robot.

Does any specific activity trigger this vulnerability?

The flaw is triggered when an attacker successfully sends specifically crafted, expired trajectory data to a system running the library. The vulnerability does not manifest during normal operation where only valid, current sensor data is processed. Simply running the software without receiving malicious, out-of-date inputs through the network pipeline does not initiate the unsafe motion behavior.

Why might Halo Surface Signal label this as low risk?

Halo Surface Signal notes that EGO-Planner-v2 is intended for internal robotics control systems and local onboard processing rather than internet-facing services. While the vulnerability technically allows network-based interaction, most deployments are localized within the robot's hardware or internal networks, making remote exploitation from the internet significantly less likely than for standard web-based applications.

What should I do if I use EGO-Planner-v2?

Your first step is to locate all systems running EGO-Planner-v2 within your infrastructure. Once identified, evaluate whether these units are connected to external networks or reachable by untrusted actors. Collaborate with your robotics and embedded systems teams to assess the criticality of these navigation functions and prioritize the deployment of software updates or mitigations to secure the trajectory handling pipeline.

References