OVERVIEW CVE-2026-41144 is a critical logic vulnerability in F Prime (F Prime) framework versions prior to 4.2.0, which is used for developing spaceflight and embedded software applications. The vulnerability stems from an integer overflow in bounds checking combined with insufficient path sanitization, allowing attackers to write arbitrary data to any file location. SEVERITY The vulnerability has a network attack vector with low complexity and requires no authentication or user interaction, making it highly accessible to potential attackers. Two distinct flaws converge to enable exploitation: first, a U32 integer overflow in the bounds check (byteOffset + dataSize > fileSize) that wraps around on overflow, and second, the complete absence of destination file path validation. The combined impact is arbitrary file write capabilities at any offset, enabling remote code execution on affected embedded targets. While the CVSS score indicates informational severity, this appears inconsistent with the actual RCE impact and should be treated as a critical finding. EXPLOITATION STATUS The vulnerability is not currently listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, and no public exploit code is confirmed available. However, it appears on the Active Hot List, indicating active community monitoring and concern. The low EPSS score (0.001) suggests limited current exploit prevalence, but the straightforward nature of the vulnerability and its RCE potential warrant immediate patching of F Prime deployments, particularly those in critical spaceflight and embedded systems environments. Patch version 4.2.0 is available with no documented workarounds.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
4.1.1CPE matchmatch criteria | cpe:2.3:a:nasa:fprime:4.1.1:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.