type: incident ยท created: 2026-08-21 ยท updated: 2026-08-21 ยท tags: [incident, vulnerability-research, space, ground-systems, command-and-control] ยท confidence: medium ยท affected_sectors: [defence, technology] ยท au_impact: false
NASA AIT-GUI Flaws Could Let Unauthenticated Attackers Issue Spacecraft Commands
Cycode researchers disclosed flaws in NASA/JPL's open-source AMMOS Instrument Toolkit (AIT) operator console (AIT-GUI) that could let an unauthenticated attacker post commands to the command bus for connected spacecraft and instruments.
Key Facts
| Field | Detail |
|---|---|
| Product | AMMOS Instrument Toolkit operator console (AIT-GUI) |
| Chain advisory | GHSA-p9r8-2q67-fp86 |
| CVSS | 9.4 rating |
| Affected versions | 2.5.1 and earlier; advisory lists 2.5.2 as fixed |
| Root cause | Web server bound to a hardcoded 0.0.0.0:8080, exposing command, script and sequence routes without authentication |
| Status | Vendor-disclosed research; no in-the-wild claims |
Impact
Per the researchers, the blast radius is measured in issued instrument commands, not defaced pages: an attacker able to reach the AIT-GUI web interface could issue commands to connected spacecraft and instruments. Mission ground-system software is an attack surface even when it ships as open source.