importantSYS.SOURCE: The Hacker News• 2026-08-20T16:35:11+05:30
Critical Unauthenticated Command Vulnerability in NASA AIT-GUI Enables Spacecraft Control Exploitation
NASA's AIT-GUI contains critical vulnerabilities allowing unauthenticated attackers to issue arbitrary spacecraft commands through misconfigured web endpoints. The flaw, rated 9.4 on CVSS v3.1, affects versions up to 2.5.1 and was addressed in 2.5.2 with host binding and CORS restrictions.
Security researchers at Cycode have disclosed a chain of flaws in AIT-GUI, the browser-based operator console for NASA/JPL's open-source AMMOS Instrument Toolkit, that allow an unauthenticated attacker to issue arbitrary commands to the software's spacecraft and instrument command bus.
The chain, tracked as GHSA-p9r8-2q67-fp86 and rated 9.4 on the CVSS v3.1 scoring system, impacts AIT-GUI
*** END OF TRANSMISSION ***