started · updated
Cybersecurity researchers disclose critical SAML and NASA software flaws
Security researchers have identified critical vulnerabilities in two distinct software environments. Using Anthropic’s Claude AI, researchers at Oblique Security uncovered flaws in Security Assertion Markup Language (SAML) implementations. These vulnerabilities, which include SAML signature wrapping, could allow attackers to bypass authentication and take over user accounts in projects such as Authentik, PHP litesaml/lightsaml, OneUptime, and Java saml-client.
Separately, Cycode researchers disclosed a high-severity vulnerability chain in NASA/JPL’s AIT-GUI, a browser-based console for the open-source AMMOS Instrument Toolkit. The flaws, rated 9.4 on the CVSS scale, could allow unauthenticated attackers to issue arbitrary commands to spacecraft and instruments. The issue stems from a lack of authentication, authorization, and CSRF protection, as well as unvalidated input that allows for path traversal and server-side script execution.