< Back to situations

Monitor this situation.

[SITUATION] · [QUIET] · [TECHNOLOGY]

2 clusters · 8 sources · 3 days · First seen · Last updated

NASA spacecraft software vulnerabilities and security risks

Overview

Cybersecurity researchers identified critical vulnerabilities in NASA/JPL’s AIT-GUI, an open-source browser-based console for the AMMOS Instrument Toolkit. These flaws, rated 9.4 on the CVSS scale, could allow unauthenticated attackers to issue arbitrary commands to spacecraft and instruments through path traversal and server-side script execution.

Following these disclosures, NASA patched the vulnerability in the AIT-GUI software, which is used to monitor spacecraft and transmit instructions. Concurrently, the U.S. Government Accountability Office (GAO) urged NASA to improve its cybersecurity risk management. The GAO report noted that NASA has not implemented a priority recommendation to conduct an organization-wide cybersecurity risk assessment and currently has 46 open recommendations that have remained unimplemented since August 2025.

Entities

Cycode · NASA · Claude AI · Anthropic · JPL

Timeline

  1. 21 days ago

    [TECHNOLOGY] 2 sources
    NASA urged to strengthen cybersecurity amid spacecraft software vulnerabilities

    NASA faces pressure from the GAO to improve cybersecurity risk management while simultaneously patching a critical software flaw that allowed unauthorized command execution on spacecraft mission control systems

  2. 23 days ago

    [TECHNOLOGY] 6 sources
    Cybersecurity researchers disclose critical SAML and NASA software flaws

    Researchers have discovered critical security flaws: Claude AI helped uncover SAML authentication bypasses, while vulnerabilities in NASA/JPL's AIT-GUI could allow unauthenticated spacecraft commands.

Sources

countryrebel.com · cybernoz.com · flagthis.com · invitehealth.substack.com · it-boltwise.de · pcauthority.com.au · thehackernews.com · worldstockmarket.net