Digest
CRITICAL

NASA AIT-GUI Flaws Allow Unauthenticated Spacecraft Command Execution

Security researchers at Cycode have discovered a chain of flaws in NASA/JPL’s open-source AMMOS Instrument Toolkit (AIT-GUI), a browser-based operator console. These vulnerabilities (GHSA-p9r8-2q67-fp86, CVSS 9.4) allow unauthenticated attackers to issue arbitrary commands to the software’s spacecraft and instrument command bus. This represents a severe risk to space mission operations.

← Back to the feed

Trending Tags