Opensatkit is a niche satellite-operations software toolkit where identified vulnerabilities center on memory-safety and file-system access issues, specifically stack-based buffer overflows and path-traversal flaws. These weakness classes reflect the toolkit's role in handling untrusted satellite telemetry and file operations in resource-constrained ground-station environments. Current severity, exploitation, and exposure metrics are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Opensatkit over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-70085CRITICAL An issue was discovered in OpenSatKit 2.2.1. The EventErrStr buffer has a fixed size of 256 bytes. The code uses sprintf to format two filenames (Source1Filename and the string ret | Feb 11, 2026 | 9.8 | 29 | NO | NO |
CVE-2025-70084HIGH Directory traversal vulnerability in OpenSatKit 2.2.1 allows attackers to gain access to sensitive information or delete arbitrary files via crafted value to the FileUtil_GetFileIn | Feb 11, 2026 | 7.5 | 24 | NO | NO |
CVE-2025-70083HIGH An issue was discovered in OpenSatKit 2.2.1. The DirName field in the telecommand is provided by the ground segment and must be treated as untrusted input. The program copies DirNa | Feb 11, 2026 | 7.8 | 23 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Opensatkit.
Media articles that mention a CVE ID that affects a product developed by Opensatkit — matched by CVE ID, not by vendor name.