CRITICAL9.8
PYSEC-2025-114
Details
A template injection vulnerability in the Dashboard of NASA Fprime v3.4.3 allows attackers to execute arbitrary code via uploading a crafted Vue file.
Are you affected?
Enter the version of the package you're using.
Affected packages
PyPI/fprime
Introduced in:
0No fixed version published yet for fprime (pip). Pin to a known-safe version or switch to an alternative.