Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
NASA’s AIT-GUI Vulnerabilities Pose Severe Security Risks

NASA’s AIT-GUI Vulnerabilities Pose Severe Security Risks

Posted on August 20, 2026 By CWS

Significant security vulnerabilities have been discovered in the AIT-GUI, a key component of NASA’s open-source AMMOS Instrument Toolkit, threatening the security of spacecraft command systems. Disclosed by Cycode, these flaws allow unauthorized users to send arbitrary commands, posing a critical risk to NASA’s operations.

Details of the Vulnerability

The vulnerabilities, cataloged as GHSA-p9r8-2q67-fp86, received a high severity score of 9.4 on the CVSS v3.1 scale. They impact AIT-GUI versions up to 2.5.1, with fixes implemented in version 2.5.2. Despite the severity, no CVE was assigned. These flaws enable unauthorized command execution due to the software’s inadequate authentication mechanisms.

Researchers highlighted that the AIT-GUI web server, by default, binds to all network interfaces, exposing critical routes without authentication or CSRF protection. This configuration allows for command issuing, script execution, and command sequence running through unprotected routes, increasing the risk of unauthorized access.

Security Measures and Fixes

Version 2.5.2, released on August 12, 2026, addresses these vulnerabilities by restricting network binding to localhost and implementing origin checks for state-changing requests. This update mitigates cross-origin request attacks, although non-browser clients remain unaffected.

However, the updated version still issues session cookies without credential verification, leaving some vulnerabilities unaddressed. The release history on PyPI shows discrepancies, with the latest available package being 2.4.1, complicating the tracking of fixes and vulnerabilities.

Ongoing Concerns and Future Outlook

Despite the release of version 2.5.2, concerns remain regarding complete resolution. A parallel vulnerability, CVE-2026-60112, further highlights authentication gaps in previous versions. Different sources provide conflicting information on the affected versions and fixes, underscoring the need for thorough verification and continuous monitoring.

This incident emphasizes the importance of robust security measures in mission-critical systems like those used by NASA. As technology evolves, collaborative efforts between human researchers and AI tools, as seen in the Cycode study, will likely play a crucial role in identifying and resolving such vulnerabilities.

Looking ahead, NASA and its partners must prioritize comprehensive security audits and updates to safeguard against potential exploitation, ensuring the integrity of space missions and the safety of spacecraft operations.

The Hacker News Tags:AIT-GUI, AMMOS, Authentication, cross-origin requests, CVE, CVSS, Cybersecurity, Cycode, NASA, path traversal, Security, software flaws, Spacecraft, Vulnerability

Post navigation

Previous Post: Expired Visa Cards Vulnerable to Contactless Payment Hack
Next Post: AI Tool Strengthens Satellite Security After Russian Cyberattack

Related Posts

OpenAI Disrupts Russian, North Korean, and Chinese Hackers Misusing ChatGPT for Cyberattacks OpenAI Disrupts Russian, North Korean, and Chinese Hackers Misusing ChatGPT for Cyberattacks The Hacker News
Cyber Espionage Campaign Hits Russian Aerospace Sector Using EAGLET Backdoor Cyber Espionage Campaign Hits Russian Aerospace Sector Using EAGLET Backdoor The Hacker News
Europol Dismantles SIM Farm Network Powering 49 Million Fake Accounts Worldwide Europol Dismantles SIM Farm Network Powering 49 Million Fake Accounts Worldwide The Hacker News
Crypto Wallet Flaw ‘Ill Bloom’ Leads to .1 Million Theft Crypto Wallet Flaw ‘Ill Bloom’ Leads to $3.1 Million Theft The Hacker News
Hackers Exploit Fake Resumes to Launch Crypto Miners Hackers Exploit Fake Resumes to Launch Crypto Miners The Hacker News
APT28’s New PRISMEX Malware Campaign Targets Ukraine APT28’s New PRISMEX Malware Campaign Targets Ukraine The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Trump Appoints Clayton to Lead Federal AI Task Force
  • South Korea Initiates Security Overhaul After Bank Data Breaches
  • China-Linked TA419 Targets U.S. AI Experts with Phishing
  • Key Arrest in ShinyHunters Case Aids FBI Investigation
  • Vercel Unveils KVM Zero-Day Flaw, Rewards Researcher $50K

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • October 2026
  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Trump Appoints Clayton to Lead Federal AI Task Force
  • South Korea Initiates Security Overhaul After Bank Data Breaches
  • China-Linked TA419 Targets U.S. AI Experts with Phishing
  • Key Arrest in ShinyHunters Case Aids FBI Investigation
  • Vercel Unveils KVM Zero-Day Flaw, Rewards Researcher $50K

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark