logo

NASA Ground Control Software Flaw Enables Unauthenticated Commands

ID: e7b6b928-eae6-5080-8d93-74dc7648eda5

STIX ID: report--e7b6b928-eae6-5080-8d93-74dc7648eda5

Feed Name: Infosecurity Magazine (News)

Threat Score
80/100

Date Published: 2026-08-18

Date Updated: 2026-08-18

...
...

A critical vulnerability (GHSA-p9r8-2q67-fp86, CVSS 9.4) was discovered in NASA's open-source AMMOS Instrument Toolkit (AIT-GUI) through version 2.5.1 that exposes unauthenticated API endpoints and insecure file-path handling, enabling attackers to issue spacecraft/instrument commands and execute scripts or command sequences; the flaw permits CSRF-based attacks from an operator's browser and was fixed in AIT-GUI 2.5.2 with recommendations to add authentication/authorization, CSRF protection, host binding, and path confinement.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.