{"id":"GHSA-prxj-3gcv-cqrh","aliases":["GO-2026-5553"],"url":"https://o3.security/vulnerability/GHSA-prxj-3gcv-cqrh","summary":"Tesla Fleet Telemetry allows spoofing telemetry for arbitrary vehicles via compromised vehicle credentials","details":"### Summary\nA vulnerability in vehicle authentication allows  threat actor with valid client credentials (i.e., a private key and certificate from a rooted infotainment system) to impersonate arbitrary VINs when authenticating to the telemetry server.\n\n### Impact\nThe attacker would be able to submit falsified telemetry records for arbitrary VINs.","published":"2026-04-01T23:01:38Z","modified":"2026-06-25T23:11:48.237235765Z","cvss":{"score":5.9,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Go","name":"github.com/teslamotors/fleet-telemetry","fixedVersion":"0.9.0"}],"fix":{"url":"https://github.com/teslamotors/fleet-telemetry/commit/d5ca0dab55812029fd38eb77f079f74ce4f47286","label":"teslamotors/fleet-telemetry@d5ca0da"},"references":[{"type":"WEB","url":"https://github.com/teslamotors/fleet-telemetry/security/advisories/GHSA-prxj-3gcv-cqrh"},{"type":"WEB","url":"https://github.com/teslamotors/fleet-telemetry/commit/d5ca0dab55812029fd38eb77f079f74ce4f47286"},{"type":"PACKAGE","url":"https://github.com/teslamotors/fleet-telemetry"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-06-25T23:11:48.237235765Z"}}