<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[NASA AIT-GUI Flaws Could Let Unauthenticated Attackers Issue Spacecraft Commands]]></title><description><![CDATA[<p dir="auto">Security researchers at Cycode have disclosed a vulnerability chain in <strong>AIT-GUI</strong>, the browser-based operator console for NASA/JPL's open-source <strong>AMMOS Instrument Toolkit (AIT)</strong>. The flaws, if exploited, could allow an unauthenticated attacker to issue arbitrary commands to the spacecraft and instrument command bus managed by the software.</p>
<p dir="auto">The chain is tracked as <strong>GHSA-p9r8-2q67-fp86</strong> and carries a <strong>9.4 CVSS v3.1</strong> severity rating. It affects AIT-GUI deployments that use the platform's built-in authentication mechanisms. The vulnerabilities stem from improper input validation and insufficient authorization checks across multiple endpoints, which can be chained together to bypass security controls entirely.</p>
<ul>
<li><strong>Impact</strong>: Successful exploitation grants full command execution capabilities without requiring any user credentials.</li>
<li><strong>Affected component</strong>: AIT-GUI, part of the AMMOS Instrument Toolkit used for deep space mission operations.</li>
<li><strong>Risk</strong>: Potential for unauthorized manipulation of spacecraft telemetry or command sequences.</li>
</ul>
<p dir="auto">Cycode has coordinated with NASA/JPL on responsible disclosure, and patches have been released in the latest AIT-GUI update. Users are strongly advised to update their installations immediately and restrict network access to the console to trusted segments only.</p>
<p dir="auto">Source: <a href="https://thehackernews.com/2026/08/nasa-ait-gui-flaws-could-let.html" target="_blank" rel="noopener noreferrer nofollow ugc">The Hacker News</a></p>
<p dir="auto">Does your team operate any mission-critical web consoles that could face similar unauthenticated command injection risks, and what steps are you taking to isolate them?</p>
]]></description><link>https://xploitlk.com/topic/79/nasa-ait-gui-flaws-could-let-unauthenticated-attackers-issue-spacecraft-commands</link><generator>RSS for Node</generator><lastBuildDate>Sat, 05 Sep 2026 13:28:54 GMT</lastBuildDate><atom:link href="https://xploitlk.com/topic/79.rss" rel="self" type="application/rss+xml"/><pubDate>Mon, 24 Aug 2026 06:30:23 GMT</pubDate><ttl>60</ttl></channel></rss>