AIT-GUI unauthenticated command execution security flaw
Vulnerability
Summary
Hide ▲
Show ▼
AIT-GUI has a critical unauthenticated command-execution vulnerability affecting versions through 2.5.1, with a fix in 2.5.2. Attackers could reach /cmd, /script/run, and /seq through browser-compatible requests because the state-changing endpoints lacked authentication, authorization, and CSRF protection. The flaw exposes spacecraft and instrument command infrastructure to unauthorized use from the browser path.
Related Happenings
CDP-Enable-BOF activates Chrome DevTools Protocol inside live Windows browsers for post-exploitation session access
Technical Analysis
H score23
First: 14.08.2026 14:07
Last: 14.08.2026 14:07
Sources 1
About this happening:
CDP-Enable-BOF now enables Chrome DevTools Protocol access inside a live Google Chrome or Microsoft Edge process on Windows, raising the risk of cookie theft...
CDP-Enable-BOF activates Chrome DevTools Protocol inside live Windows browsers for post-exploitation session access
Technical AnalysisAbout this happening: CDP-Enable-BOF now enables Chrome DevTools Protocol access inside a live Google Chrome or Microsoft Edge process on Windows, raising the risk of cookie theft...
Timeline
-
18.08.2026 17:30 3 articles · 13d ago
Cycode discloses critical AIT-GUI command-execution flaw
Initial DisclosureCycode researcher Yuval Elbar disclosed a critical vulnerability in NASA's open-source AMMOS Instrument Toolkit (AIT)-GUI ground software that affects versions through 2.5.1 and was fixed in AIT-GUI 2.5.2. The flaw lets unauthenticated attackers issue spacecraft and instrument commands, execute server-side scripts, and run command sequences through exposed state-changing routes, with the web server starting on all network interfaces and lacking authentication, authorization, and CSRF protection.
Show sources
- NASA Ground Control Software Flaw Enables Unauthenticated Commands — www.infosecurity-magazine.com — 18.08.2026 17:30
- NASA Ground Control Software Flaw Enables Unauthenticated Commands — www.infosecurity-magazine.com — 18.08.2026 17:30
- NASA AIT-GUI Flaws Could Let Unauthenticated Attackers Issue Spacecraft Commands — thehackernews.com — 20.08.2026 14:05