CVE-2026-71644
nicheMissing FSM default case in SYSU STAR RACER can trigger unsafe UAV swarm trajectories
RACER, an open-source quadrotor swarm trajectory planner from Robotics-STAR-Lab (SYSU STAR Group), contains a finite-state-machine flaw (classified as CWE-843) in which a missing default case causes the system to stop publishing swarm trajectories when a drone enters the IDLE state, producing unsafe trajectory planning. Per the CVSS network attack vector, a remote attacker able to influence the planner can induce the IDLE state and trigger this behavior, gaining the ability to disrupt swarm coordination and potentially cause physical UAV collisions. The flaw was confirmed at commit abcdef1234567890, and no fixed version is documented in the available data. Affected users are primarily robotics researchers and academic labs running RACER for swarm-flight experiments, rather than large production fleets. No proof-of-concept exploit or in-the-wild exploitation is known, and the issue is not listed in CISA KEV.
What to do: Track the upstream RACER repository for a patched commit addressing the missing FSM default case, since no fixed version is documented; check your checked-out revision against commit abcdef1234567890 and update when a fix lands. Until then, treat IDLE transitions during active swarm flight as a known failure mode, restrict network access to the planner's interfaces, and use physical safety measures (spotters, geofencing, emergency stop) during swarm tests.
| Robotics-STAR-Lab (SYSU STAR Group) RACER | commit abcdef1234567890 (tested affected); broader affected version ranges not documented |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
An issue in Robotics-STAR-Lab (SYSU STAR Group) RACER Tested affected version: commit abcdef1234567890 allows an attacker to cause unsafe trajectory planning and potential UAV collisions via a missing default case in the FSM that stops publishing swarm trajectories when the drone enters IDLE
- Weakness
- CWE-843
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.