A critical vulnerability in NASA/JPL’s open-source AMMOS Instrument Toolkit GUI (AIT-GUI) could allow unauthenticated attackers to issue spacecraft and instrument commands, execute server-side scripts, and launch command sequences through exposed web endpoints. The flaw, tracked as GHSA-p9r8-2q67-fp86 and rated CVSS 9.4, affects AIT-GUI versions through 2.5.1 and was fixed in 2.5.2. Researchers said the application binds its HTTP server to 0.0.0.0, effectively exposing the interface on all network interfaces, while sensitive API routes lack authentication, authorization, and CSRF protections.
The vulnerable endpoints reportedly include POST /cmd for arbitrary command relay, POST /script/run for server-side script execution, and POST /seq for sequence execution, with the latter two also affected by path traversal due to unsafe path handling. Because the endpoints accept form-encoded requests, an operator visiting a malicious website could be induced to send cross-origin requests from their browser, enabling attacks even against host-local or otherwise firewalled deployments. Security researchers urged users to upgrade to AIT-GUI 2.5.2 immediately and keep the service port off untrusted networks.

See affected versions and whether adversaries are exploiting it.
4 events from the most recent confirmed update back to the earliest known activity.
The Hacker News reported that tagged AIT-GUI 2.5.2 still creates a session without credential checks and accepts requests to command-related endpoints with that session cookie. It confirmed the release narrows listening scope and blocks browser-driven cross-origin requests, but does not add authentication to the command, script, or sequence endpoints.
Cycode researcher Yuval Elbar disclosed a critical vulnerability in NASA's open-source AMMOS Instrument Toolkit GUI (AIT-GUI) that could let unauthenticated attackers issue spacecraft and instrument commands, execute server-side scripts, and run command sequences. The issue is tracked as GHSA-p9r8-2q67-fp86 and was rated CVSS 9.4.
A related AIT-GUI vulnerability, CVE-2026-60112, was published describing a missing-authentication flaw that lets attackers create a valid session without credential checks and forward arbitrary commands to the AIT command bus. The reference says the issue carries a CVSS v3.1 score of 9.8.
The vulnerability affecting AIT-GUI versions through 2.5.1 was fixed in version 2.5.2. The flaw involved the web server binding to all interfaces and lacking authentication, authorization, CSRF protections, and proper path confinement on sensitive routes.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
6 references tracked. Mallory keeps watching after this page renders.
securityaffairs.com
Open sourcescworld.com
Open sourcecybersecuritynews.com
Open sourcethehackernews.com
Open sourcecycode.com
Open sourceinfosecurity-magazine.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.