Insights ·

NASA AIT-GUI spacecraft command vulnerability disclosure

By Nanorisk

NASA AIT-GUI spacecraft command vulnerability disclosure

Cycode have disclosed a vulnerability chain in AIT-GUI, the browser-based operator console for NASA/JPL's open-source AMMOS Instrument Toolkit, tracked as GHSA-p9r8-2q67-fp86 and rated 9.4 on CVSS v3.1. The chain allows an unauthenticated attacker to issue arbitrary commands to the spacecraft and instrument command bus. No credentials. No prior access. Direct command execution against critical systems.

The wider point here is about open-source tooling in high-consequence environments. There's a tendency to treat widely adopted open-source software as having been implicitly reviewed because it's publicly visible or community-maintained. That assumption is flawed. Visibility is not the same as scrutiny, and community maintenance is not the same as security testing.

If your organisation uses open-source components anywhere near operational infrastructure, those components need the same structured assessment as anything else in scope. The attack surface doesn't care about the licensing model.

Concerned this affects you?

We can assess your exposure and tell you plainly where you stand.

← All insights