Find notable cyber news and cases, enriched with sources, timelines, and signals.

AIT-GUI unauthenticated command execution security flaw

Vulnerability
First reported
Last updated
Happening score
H score 32
2 unique sources, 2 articles

Summary

Hide ▲

AIT-GUI has a critical unauthenticated command-execution vulnerability affecting versions through 2.5.1, with a fix in 2.5.2. Attackers could reach /cmd, /script/run, and /seq through browser-compatible requests because the state-changing endpoints lacked authentication, authorization, and CSRF protection. The flaw exposes spacecraft and instrument command infrastructure to unauthorized use from the browser path.

Related Happenings

CDP-Enable-BOF activates Chrome DevTools Protocol inside live Windows browsers for post-exploitation session access

Technical Analysis
H score23 First: 14.08.2026 14:07 Last: 14.08.2026 14:07 Sources 1

About this happening: CDP-Enable-BOF now enables Chrome DevTools Protocol access inside a live Google Chrome or Microsoft Edge process on Windows, raising the risk of cookie theft...

Timeline

  1. 18.08.2026 17:30 3 articles · 13d ago

    Cycode discloses critical AIT-GUI command-execution flaw

    Initial Disclosure

    Cycode researcher Yuval Elbar disclosed a critical vulnerability in NASA's open-source AMMOS Instrument Toolkit (AIT)-GUI ground software that affects versions through 2.5.1 and was fixed in AIT-GUI 2.5.2. The flaw lets unauthenticated attackers issue spacecraft and instrument commands, execute server-side scripts, and run command sequences through exposed state-changing routes, with the web server starting on all network interfaces and lacking authentication, authorization, and CSRF protection.

    Show sources