NASA's Open-Source Ground Systems Expose Spacecraft to Unauthenticated Command Takeover
5 Articles
5 Articles
NASA's Open-Source Ground Systems Expose Spacecraft to Unauthenticated Command Takeover
A critical vulnerability in software used to command NASA spacecraft sat exposed for anyone with network reach. Researchers at security firm Cycode uncovered the flaw in the agency’s AMMOS Instrument Toolkit. The issue affects the browser-based operator console known as AIT-GUI. It carries a CVSS score of 9.4. And the consequences could have been catastrophic. Yuval Elbar, a researcher with Cycode, disclosed the problem on August 18. Versions of…
NASA's ground control software has a worrying security flaw which could let hackers contact spacecraft
NASA’s ground control software has a critical vulnerability that could allow third-party access to spacecraftThe flaw has been found in a browser-based variant of NASA’s AMMOS Instrument ToolkitNASA has not publicly responded to the flaw’s disclosureNASA’s open source ground control software has a critical vulnerability that could enable an unauthenticated attacker to gain access and take control of spacecraft. The AMMOS Instrument Toolkit’s bro…
A cybersecurity researcher has discovered a vulnerability in open-source software used by NASA for ground control. By exploiting it, a hacker could take control of spacecraft. [Read more] Download our Android and iOS app! You can read our articles, features, and watch our latest YouTube videos.
Critical NASA AIT-GUI Flaw Lets Unauthenticated Attackers Issue Spacecraft Commands
A critical security flaw in NASA/JPL’s open-source AMMOS Instrument Toolkit GUI (AIT-GUI) could let an unauthenticated attacker send live commands to spacecraft and scientific instruments, run arbitrary scripts, and execute command sequences without ever logging in. Security researcher Yuval Elbar of Cycode disclosed an issue rated 9.4 on the CVSS v3.1 scale on August 13, 2026. This issue has been patched in AIT-GUI version 2.5.2, which was rele…
NASA AIT-GUI Flaws Could Let Unauthenticated Attackers Issue Spacecraft Commands
Security researchers at Cycode have disclosed a chain of flaws in AIT-GUI, the browser-based operator console for NASA/JPL's open-source AMMOS Instrument Toolkit, that allow an unauthenticated attacker to issue arbitrary commands to the software's spacecraft and instrument command bus. The chain, tracked as GHSA-p9r8-2q67-fp86 and rated 9.4 on the CVSS v3.1 scoring system, impacts AIT-GUI
Coverage Details
Bias Distribution
- 100% of the sources are Center
Factuality
To view factuality data please Upgrade to Premium






