CVE-2025-59534Disclosure(nasa / cryptolib)

LOWCVSS 7.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

CryptoLib provides a software-only solution using the CCSDS Space Data Link Security Protocol - Extended Procedures (SDLS-EP) to secure communications between a spacecraft running the core Flight System (cFS) and a ground station. Prior to version 1.4.2, there is a command Injection vulnerability in initialize_kerberos_keytab_file_login(). The vulnerability exists because the code directly interpolates user-controlled input into a shell command and executes it via system() without any sanitization or validation. This issue has been patched in version 1.4.2.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-78

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • cryptolib

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • 1 total mentions across 1 day

Affected systems

Vendors
Products
cryptolib

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-02-10: 1Technical Details · 2026-02-10: 102-10
Signal classification1 categories
Disclosure
1100.0%
Referenced assets1 URL
By indicator
Full discourse1 post
  • Caleb Gross@noperator
    Disclosure

    6/ Beyond N-day, SiftRank generalizes to 0-day. In 45 seconds, it reproduces discovery of CVE-2025-59534, a command injection in NASA’s CryptoLib. It ranks the vulnerable function #1 out of 286 for this vuln class. https://github.com/nasa/CryptoLib/security/advisories/GHSA-jw5c-58hr-m3v3 https://t.co/kwsZhvQ7nD

    Post summary

    The post reports that the SiftRank tool quickly identified CVE-2025-59534, a command injection in NASA's CryptoLib, offering technical details but no mention of patches, exploits, or active attacks.

    1001621.0K
    2.1K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appnasacryptolib---

Explore more