PT-2026-30197 · Nasa · Cfs

0Rbitingzer0

·

Published

2026-04-03

·

Updated

2026-04-03

·

CVE-2026-5473

CVSS v3.1

4.5

Medium

AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L
A vulnerability has been found in NASA cFS up to 7.0.0. The impacted element is the function pickle.load of the component Pickle Module. Such manipulation leads to deserialization. The attack needs to be performed locally. The attack requires a high level of complexity. The exploitability is regarded as difficult. The exploit has been disclosed to the public and may be used. The project was informed of the problem early through an issue report but has not responded yet.

Fix

RCE

Deserialization of Untrusted Data

Weakness Enumeration

Related Identifiers

CVE-2026-5473

Affected Products

Cfs