[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"focus:nasa-ait-gui-flaws-could-let-unauthenticated-attackers-issue-spacecraft-commands-mt1pqjgr":3},{"item":4},{"id":5,"title":6,"slug":7,"summary":8,"severity":9,"category":10,"cve_ids":11,"affected_products":12,"action_required":16,"article_ids":17,"ioc_summary":19,"source_urls":20,"status":22,"expires_at":23,"created_at":24,"updated_at":25,"articles":26},"3dae21d1-05ae-4e2d-b1a0-8ff47c7f0ef0","NASA AIT-GUI Flaws Could Let Unauthenticated Attackers Issue Spacecraft Commands","nasa-ait-gui-flaws-could-let-unauthenticated-attackers-issue-spacecraft-commands-mt1pqjgr","NASA's AIT-GUI spacecraft control software contains critical unauthenticated command injection vulnerabilities (CVSS 9.4) allowing attackers to execute arbitrary commands and scripts without authentication. Any organization running AIT-GUI versions below 2.5.2 is at immediate risk of losing control of spacecraft systems or connected instruments. The patched version exists but most deployed instances are still on vulnerable 2.4.1 from PyPI.","critical","advisory",[],[13,14,15],"NASA","AIT-GUI","Cycode","Identify all systems running AIT-GUI in your environment immediately. Upgrade to version 2.5.2 or newer without delay. If you cannot patch within 24 hours, isolate affected systems from network access until patching is complete.",[18],"2c5d0f0d-0933-47f9-9f20-c1303b59d2c3",null,[21],"https:\u002F\u002Fthehackernews.com\u002F2026\u002F08\u002Fnasa-ait-gui-flaws-could-let.html","archived","2026-08-22T16:06:26.823+00:00","2026-08-20T16:06:32.800769+00:00","2026-08-22T17:05:46.110238+00:00",[27],{"id":18,"title":6,"url":21}]