www.infosecurity-magazine.com 8/18/2026, 2:50:52 PM · external

NASA’s AMMOS Toolkit bug lets hackers send commands to spacecraft

NASA’s AMMOS Toolkit bug lets hackers send commands to spacecraft

A serious vulnerability has been discovered in NASA's open-source AMMOS Instrument Toolkit (AIT)-GUI, allowing unauthenticated attackers to issue commands to spacecraft and execute scripts. This flaw, tracked as GHSA-p9r8-2q67-fp86 and given a CVSS rating of 9.4, affects AIT-GUI versions up to 2.5.1. The issue lies in the API's lack of authentication and CSRF protection, enabling potential exploitation even without direct access to the server.

Recommendations for addressing the vulnerability include implementing authentication measures, CSRF protection, and binding the server to its configured host. The flaw has been patched in version 2.5.2.

View full article

Article by CyberSIXT