CVE Tools
Back to feed
Patch released AIT-GUI ics-ot-iot AMMOS Instrument Toolkit NASA JPL auth-bypass

NASA AIT-GUI Flaws Could Let Unauthenticated Attackers Issue Spacecraft Commands

The Hacker News·By The Hacker News··5 min read
CVE Tools coverage

Researchers at Cycode revealed that vulnerabilities in AIT-GUI, the browser-based console for NASA/JPL's AMMOS Instrument Toolkit, allowed unauthenticated actors to send arbitrary commands to spacecraft instruments. Identified as GHSA-p9r8-2q67-fp86 with a CVSS score of 9.4, the flaw impacted versions up to 2.5.1 because the server bound to all interfaces without requiring credentials or CSRF protection. Version 2.5.2 resolves these issues by restricting network bindings and enforcing origin checks on state-changing requests, though related records like CVE-2026-60112 highlight ongoing discrepancies regarding full authentication enforcement.