logo

Critical Flaw in NASA/JPL Open-Source Spacecraft Command Software Allowed Unauthenticated Command Execution

ID: ec5ace1c-48bb-530a-bd3b-e0098d692c48

STIX ID: report--ec5ace1c-48bb-530a-bd3b-e0098d692c48

Feed Name: Security Affairs

Threat Score
80/100

Date Published: 2026-08-22

Date Updated: 2026-08-22

Author: Pierluigi Paganini

...
...

A critical vulnerability in NASA/JPL’s open-source AIT-GUI (GHSA-p9r8-2q67-fp86, CVSS 9.4) allowed unauthenticated command execution, server-side script runs, and path-traversal on sequence/script endpoints due to lack of authentication, CSRF protection, session checks, and proper host binding. Researchers produced PoCs (including a CSRF demonstration) and the issue is fixed in AIT-GUI 2.5.2; operators are advised to upgrade immediately, audit exposed instances, and apply authentication, CSRF protection, host binding, and path-confinement fixes.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.