Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
NASA’s AIT-GUI Vulnerabilities Pose Severe Security Risks

NASA’s AIT-GUI Vulnerabilities Pose Severe Security Risks

Posted on August 20, 2026 By CWS

Significant security vulnerabilities have been discovered in the AIT-GUI, a key component of NASA’s open-source AMMOS Instrument Toolkit, threatening the security of spacecraft command systems. Disclosed by Cycode, these flaws allow unauthorized users to send arbitrary commands, posing a critical risk to NASA’s operations.

Details of the Vulnerability

The vulnerabilities, cataloged as GHSA-p9r8-2q67-fp86, received a high severity score of 9.4 on the CVSS v3.1 scale. They impact AIT-GUI versions up to 2.5.1, with fixes implemented in version 2.5.2. Despite the severity, no CVE was assigned. These flaws enable unauthorized command execution due to the software’s inadequate authentication mechanisms.

Researchers highlighted that the AIT-GUI web server, by default, binds to all network interfaces, exposing critical routes without authentication or CSRF protection. This configuration allows for command issuing, script execution, and command sequence running through unprotected routes, increasing the risk of unauthorized access.

Security Measures and Fixes

Version 2.5.2, released on August 12, 2026, addresses these vulnerabilities by restricting network binding to localhost and implementing origin checks for state-changing requests. This update mitigates cross-origin request attacks, although non-browser clients remain unaffected.

However, the updated version still issues session cookies without credential verification, leaving some vulnerabilities unaddressed. The release history on PyPI shows discrepancies, with the latest available package being 2.4.1, complicating the tracking of fixes and vulnerabilities.

Ongoing Concerns and Future Outlook

Despite the release of version 2.5.2, concerns remain regarding complete resolution. A parallel vulnerability, CVE-2026-60112, further highlights authentication gaps in previous versions. Different sources provide conflicting information on the affected versions and fixes, underscoring the need for thorough verification and continuous monitoring.

This incident emphasizes the importance of robust security measures in mission-critical systems like those used by NASA. As technology evolves, collaborative efforts between human researchers and AI tools, as seen in the Cycode study, will likely play a crucial role in identifying and resolving such vulnerabilities.

Looking ahead, NASA and its partners must prioritize comprehensive security audits and updates to safeguard against potential exploitation, ensuring the integrity of space missions and the safety of spacecraft operations.

The Hacker News Tags:AIT-GUI, AMMOS, Authentication, cross-origin requests, CVE, CVSS, Cybersecurity, Cycode, NASA, path traversal, Security, software flaws, Spacecraft, Vulnerability

Post navigation

Previous Post: Expired Visa Cards Vulnerable to Contactless Payment Hack
Next Post: AI Tool Strengthens Satellite Security After Russian Cyberattack

Related Posts

Malicious Rust Crates Steal Solana and Ethereum Keys — 8,424 Downloads Confirmed Malicious Rust Crates Steal Solana and Ethereum Keys — 8,424 Downloads Confirmed The Hacker News
Automation Is Redefining Pentest Delivery Automation Is Redefining Pentest Delivery The Hacker News
You Didn’t Get Phished — You Onboarded the Attacker You Didn’t Get Phished — You Onboarded the Attacker The Hacker News
Accelerating Exploit Timelines Challenge Defenders Accelerating Exploit Timelines Challenge Defenders The Hacker News
Russian Hackers Using ClickFix Fake CAPTCHA to Deploy New LOSTKEYS Malware Russian Hackers Using ClickFix Fake CAPTCHA to Deploy New LOSTKEYS Malware The Hacker News
Is Your Business Prepared for Agent AI Challenges? Is Your Business Prepared for Agent AI Challenges? The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Cisco Patches Critical XML Vulnerability in BroadWorks
  • MLflow Flaw Exploited for Credential Theft in Cloud
  • ToxicPanda 2.0 and GoldDigger Amplify Android Threats
  • Malicious Firefox Extensions Target Crypto Wallets
  • AI Tool Strengthens Satellite Security After Russian Cyberattack

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Cisco Patches Critical XML Vulnerability in BroadWorks
  • MLflow Flaw Exploited for Credential Theft in Cloud
  • ToxicPanda 2.0 and GoldDigger Amplify Android Threats
  • Malicious Firefox Extensions Target Crypto Wallets
  • AI Tool Strengthens Satellite Security After Russian Cyberattack

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark