NASA AIT-GUI Flaws Could Let Unauthenticated Attackers Issue Spacecraft Commands
PatchAIT-GUIAMMOS Instrument ToolkitOur summary
Researchers at Cycode revealed that vulnerabilities in AIT-GUI, the browser-based console for NASA/JPL's AMMOS Instrument Toolkit, allowed unauthenticated actors to send arbitrary commands to spacecraft instruments. Identified as GHSA-p9r8-2q67-fp86 with a CVSS score of 9.4, the flaw impacted versions up to 2.5.1 because the server bound to all interfaces without requiring credentials or CSRF protection. Version 2.5.2 resolves these issues by restricting network bindings and enforcing origin checks on state-changing requests, though related records like CVE-2026-60112 highlight ongoing discrepancies regarding full authentication enforcement.
The Hacker News publishes this story on its own site; we link to it rather than reprint it.
Worried this affects your company?
Discuss a security assessment of your internet-facing systems. Scope agreed before testing.