CNNVD-202602-1898 Information

CNNVD ID

CNNVD-202602-1898

CVE-2025-70084

  • CNNVD Published: 2026-02-11

Description (Chinese)

OpenSatKit是OpenSatKit开源的一个应用程序开发工具包。 OpenSatKit 2.2.1版本存在安全漏洞,该漏洞源于FileUtil_GetFileInfo函数存在目录遍历,可能导致攻击者获取敏感信息或删除任意文件。

Description (English)

OpenSatKit is an application development toolkit for OpenSatKit open source. OpenSatKit 2.2.1 has a security loophole that stems from the existence of the FileUtil GetFileInfo function, which may lead the assailant to obtain sensitive information or delete any file.

Vulnerability Type

其他

Affected Vendor

OpenSatKit

Published

2026-02-11

Last Modified

2026-02-24

References

https://gist.github.com/jonafk555 https://github.com/OpenSatKit/OpenSatKit https://github.com/OpenSatKit/OpenSatKit/releases/tag/v2.2.1 https://raw.githubusercontent.com/OpenSatKit/OpenSatKit/master/cfs/apps/filemgr/fsw/src/dir.c

Patch

https://github.com/OpenSatKit/OpenSatKit/releases

Share on: