logo

NASA AIT-GUI Flaws Could Let Unauthenticated Attackers Issue Spacecraft Commands

ID: 7e155cc4-4f35-5945-b0ed-91733a3a8411

STIX ID: report--7e155cc4-4f35-5945-b0ed-91733a3a8411

Feed Name: The Hacker News

Threat Score
80/100

Date Published: 2026-08-20

Date Updated: 2026-08-21

Author: [email protected] (The Hacker News)

...
...

Cycode disclosed a high-severity chain of flaws (GHSA-p9r8-2q67-fp86, CVSS 9.4) in AIT-GUI that allow unauthenticated acquisition of a session cookie and subsequent arbitrary spacecraft/instrument commanding, path traversal to run server-side scripts, and cross-origin POST delivery enabling CSRF-like attacks; fixes were released in 2.5.2 to restrict binding and block browser-driven cross-origin requests but credential-based authentication for command/script/sequence endpoints remains absent and records disagree on exact fixed versions and scope.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.