{
  "id": 2217257,
  "title": "NASA's ground control software has a worrying security flaw which could let hackers contact spacecraft",
  "url": "https://urgent.news/2026/08/20/nasas-ground-control-software-has-a-worrying-security-flaw-which",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-08-20T20:25:00.000Z",
  "source": {
    "name": "TechRadar",
    "slug": "techradar",
    "url": "https://www.techradar.com/pro/security/nasas-ground-control-software-has-a-worrying-security-flaw-which-could-let-hackers-contact-spacecraft"
  },
  "original_language": "en",
  "account": "NASA's ground control software contains a critical security flaw that could enable hackers to gain access and take control of spacecraft. The vulnerability, discovered in a browser-based version of NASA's AMMOS Instrument Toolkit (AIT), arises from the AMMOS Instrument Toolkit Graphical User Interface (AIT-GUI) tool. Versions of AIT-GUI up to 2.5.1 are susceptible, but the issue has been corrected in version 2.5.2, according to researcher Yuval Elbar.\n\nThe flaw allows an unauthenticated attacker to gain access and control of the spacecraft, execute server-side scripts, and run command sequences. The API lacks authentication and authorization protection, and the CSRF protection for changing endpoints is absent in the affected versions of AIT-GUI. This means attackers could exploit the access-control security failings, leading to potential malware or custom-built script execution on NASA spacecraft.\n\nElbar revealed the vulnerability on August 18, 2026, highlighting that the web GUI for AIT-GUI runs on every network interface and requires no password. It can be manipulated by any web page opened by an operator. Furthermore, the external access to the vulnerable AIT-GUI browser session means that attackers don't even need to be on the same network as the spacecraft. They could direct an operator to a web page hiding malicious code or simply control a web page under their own control to gain access.\n\nCycode recommends NASA administrators to upgrade AIT-GUI to version 2.5.2, run checks on the console port, and review command history to address the security flaw.",
  "summary": "Security researchers uncover flaw in the open source software used by NASA ground control to communicate with instruments and spacecraft.",
  "key_points": [
    "NASA's AMMOS Instrument Toolkit (AIT) has critical security flaw in browser-based version.",
    "Unauthenticated attacker can gain control of spacecraft via AIT-GUI vulnerability.",
    "Issue fixed in AIT-GUI version 2.5.2, recommended upgrade by Cycode."
  ],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}