Critical NASA AIT-GUI Flaws Could Let Unauthenticated Attackers Send Spacecraft Commands
A chain of vulnerabilities in AIT-GUI, the browser-based operator console for NASA/JPL's open-source AMMOS Instrument Toolkit, could allow unauthenticated attackers to issue arbitrary commands to the spacecraft and instrument command bus. The issue is tracked as GHSA-p9r8-2q67-fp86 and has a CVSS v3.1 score of 9.4.























