Junglewise Threat Intelligence

CVE-2026-5473: NASA cFS deserialization in Ground System Pickle Module

CVE-2026-5473 · Severity: medium · CVSS 4.5 · Published 2026-04-03

Technologies: Nasa Core Flight System. Vendors: Nasa.

Executive brief

A security vulnerability exists in the NASA Core Flight System (cFS) Ground System, which is used to manage and command spacecraft from Earth. An attacker with local access to the ground station computer could replace command or parameter files with malicious versions. When a mission operator opens these files, the system could execute unauthorized code, potentially leading to a full takeover of the operator's workstation and disruption of mission operations.

Technical details

A deserialization vulnerability exists in the NASA cFS Ground System (specifically within the cFS-GroundSystem component) due to the unsafe use of Python's 'pickle.load()' function. The vulnerability is located in 'UdpCommands.py', 'CommandSystem.py', and 'Parameter.py', where the system loads command and parameter definition files from disk without integrity verification. Because the 'pickle' module supports the '__reduce__' protocol, an attacker who can modify '.pickle' files in the 'CommandFiles/' or 'ParameterFiles/' directories can execute arbitrary OS commands with the privileges of the Ground System operator. This requires local access or a prior foothold on the system to modify the files. As of the advisory date, the project has been informed but a formal patch has not been confirmed.

Affected products

  • NASA cFS up to 7.0.0

Timeline

  • 2026-03-18: disclosed: Issue reported on GitHub by 0rbitingZer0
  • 2026-04-03: advisory: Vulnerability published in NVD/VulDB

References

Related threats