Home ยท Wiki ยท Incidents & Campaigns
type: incident ยท created: 2026-08-21 ยท updated: 2026-08-21 ยท tags: [incident, vulnerability-research, space, ground-systems, command-and-control] ยท confidence: medium ยท affected_sectors: [defence, technology] ยท au_impact: false

NASA AIT-GUI Flaws Could Let Unauthenticated Attackers Issue Spacecraft Commands

Cycode researchers disclosed flaws in NASA/JPL's open-source AMMOS Instrument Toolkit (AIT) operator console (AIT-GUI) that could let an unauthenticated attacker post commands to the command bus for connected spacecraft and instruments.

Key Facts

Field Detail
Product AMMOS Instrument Toolkit operator console (AIT-GUI)
Chain advisory GHSA-p9r8-2q67-fp86
CVSS 9.4 rating
Affected versions 2.5.1 and earlier; advisory lists 2.5.2 as fixed
Root cause Web server bound to a hardcoded 0.0.0.0:8080, exposing command, script and sequence routes without authentication
Status Vendor-disclosed research; no in-the-wild claims

Impact

Per the researchers, the blast radius is measured in issued instrument commands, not defaced pages: an attacker able to reach the AIT-GUI web interface could issue commands to connected spacecraft and instruments. Mission ground-system software is an attack surface even when it ships as open source.

Source