VYPR

Fprime

by Nasa

Source repositories

CVEs (7)

  • CVE-2026-72577CriAug 10, 2026
    risk 0.64cvss 9.8epss 0.01

    Multiple vulnerabilities in NASA fprime-gds through 3.4.3 allow an unauthenticated remote attacker to achieve arbitrary code execution on the ground station host and inject arbitrary commands to connected spacecraft. The Flask application in src/fprime_gds/flask/app.py applies…

  • CVE-2024-55030CriMar 25, 2025
    risk 0.64cvss 9.8epss 0.02

    A command injection vulnerability in the Command Dispatcher Service of NASA Fprime v3.4.3 allows attackers to execute arbitrary commands.

  • CVE-2024-55028CriMar 25, 2025
    risk 0.64cvss 9.8epss 0.01

    A template injection vulnerability in the Dashboard of NASA Fprime v3.4.3 allows attackers to execute arbitrary code via uploading a crafted Vue file.

  • CVE-2026-67977HigAug 3, 2026
    risk 0.49cvss 7.5epss 0.00

    An integer overflow in the Svc::FileDownlink::SendPartial component of fprime framework v4.2.2 allows attackers to cause a Denial of Service (DoS) via a crafted input.

  • CVE-2026-67976HigAug 3, 2026
    risk 0.49cvss 7.5epss 0.00

    The Ref::SignalGen component of fprime framework v4.2.2 does not validate the safety of user-controlled parameters, allowing attackers to cause a Denial of Service (DoS) via inputting unsafe parameters.

  • CVE-2024-55029MedMar 25, 2025
    risk 0.40cvss 6.1epss 0.00

    NASA Fprime v3.4.3 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities.

  • CVE-2026-41144NonApr 22, 2026
    risk 0.00cvss 0.0epss 0.00

    F´ (F Prime) is a framework that enables development and deployment of spaceflight and other embedded software applications. Prior to version 4.2.0, the bounds check byteOffset + dataSize > fileSize uses U32 addition that wraps around on overflow. An attacker-crafted DataPacket…