Home › Intelligence › Brief
VULNERABILITY BRIEF🔴 Critical Vulnerability

Critical Unauthenticated Command Injection Flaws in NASA’s AIT‑GUI Console (GHSA‑p9r8‑2q67‑fp86)

Researchers disclosed a chain of critical flaws (CVSS 9.4) in NASA/JPL’s open‑source AIT‑GUI console that let unauthenticated attackers issue arbitrary spacecraft commands. The vulnerability highlights the need for rigorous vulnerability‑management and SOC 2 evidence of remediation for government‑grade software.

LiveThreat™ Intelligence · 📅 August 20, 2026· 📰 thehackernews.com
🔴
Severity
Critical
VU
Type
Vulnerability
🎯
Confidence
High
🏢
Affected
2 sector(s)
✅
Actions
3 recommended
📰
Source
thehackernews.com

NASA AIT‑GUI Vulnerabilities Allow Unauthenticated Attackers to Issue Spacecraft Commands

What Happened – Security researchers at Cycode disclosed a chain of flaws in AIT‑GUI, the browser‑based operator console for NASA/JPL’s open‑source AMMOS Instrument Toolkit (GHSA‑p9r8‑2q67‑fp86). The vulnerabilities receive a CVSS v3.1 score of 9.4 and enable an unauthenticated remote user to inject arbitrary commands onto the spacecraft and instrument command bus.

Why It Matters for Compliance & Audit Readiness

  • The scenario maps directly to SOC 2 CC6.1 (System Operations) and CC7.1 (Risk Management) – controls that require documented vulnerability‑management and timely remediation.
  • Continuous evidence of patching and monitoring is essential to demonstrate a defensible audit trail for mission‑critical software.
  • Control‑mapping tools help translate a technical flaw into compliance artifacts that can be presented to auditors or regulators.

Who Is Affected – NASA/JPL, other government agencies, and aerospace/defense organizations that adopt the AMMOS toolkit or similar spacecraft command consoles.

Recommended Actions –

  • Add AIT‑GUI to your asset inventory and initiate a formal vulnerability scan.
  • Apply the vendor‑provided patches, then record remediation steps in your compliance platform.
  • Deploy automated monitoring of the console’s HTTP endpoints to capture continuous evidence of control effectiveness. Source: The Hacker News

Technical Notes – The attack chain exploits unauthenticated HTTP request manipulation, bypassing input validation and authentication checks to reach the command bus. CVSS 9.4 (Critical). No data exfiltration reported, but the potential impact includes unauthorized spacecraft maneuvering. Source: The Hacker News

📰 Original Source
https://thehackernews.com/2026/08/nasa-ait-gui-flaws-could-let.html ↗

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Trust Operations

Answer one control objective. Answer ten frameworks.

The Verisq Common Framework is a spine of 84 control objectives that SOC 2, ISO 27001, NIST CSF, CMMC, HIPAA, PCI DSS, HITRUST, GDPR, ISO 42001 and NIST AI RMF map onto — each graded honestly. Satisfy an objective once and every framework that recognizes it lights up at its real strength.

See how the Verisq Common Framework works →