Cycode researcher Yuval Elbar has uncovered a critical vulnerability in NASA/JPL’s open-source AIT-GUI, the browser-based console used to command spacecraft and scientific instruments.
The software shipped without authentication or authorization on sensitive endpoints, potentially allowing an attacker to issue arbitrary commands, run scripts and execute command sequences without credentials. Because it also lacked CSRF protection, an attacker could potentially exploit even a firewalled system simply by getting an operator to visit a malicious webpage.
The vulnerability carries a CVSS score of 9.4 and is tracked as GHSA-p9r8-2q67-fp86. It has been fixed in AIT-GUI 2.5.2.
The blog with full details is here: https://cycode.com/blog/ait-gui-unauthenticated-command-execution
Related
This entry was posted on August 18, 2026 at 1:54 pm and is filed under Commentary with tags Cycode. You can follow any responses to this entry through the RSS 2.0 feed.
You can leave a response, or trackback from your own site.
Critical vulnerability in NASA/JPL’s open-source AIT-GUI
Cycode researcher Yuval Elbar has uncovered a critical vulnerability in NASA/JPL’s open-source AIT-GUI, the browser-based console used to command spacecraft and scientific instruments.
The software shipped without authentication or authorization on sensitive endpoints, potentially allowing an attacker to issue arbitrary commands, run scripts and execute command sequences without credentials. Because it also lacked CSRF protection, an attacker could potentially exploit even a firewalled system simply by getting an operator to visit a malicious webpage.
The vulnerability carries a CVSS score of 9.4 and is tracked as GHSA-p9r8-2q67-fp86. It has been fixed in AIT-GUI 2.5.2.
The blog with full details is here: https://cycode.com/blog/ait-gui-unauthenticated-command-execution
Share this:
Like this:
Related
This entry was posted on August 18, 2026 at 1:54 pm and is filed under Commentary with tags Cycode. You can follow any responses to this entry through the RSS 2.0 feed. You can leave a response, or trackback from your own site.