GHSA-p6w2-c4j5-7xhmCriticalCVSS 9.8

Multiple vulnerabilities in NASA fprime-gds through 3.4.3 allow an unauthenticated remote...

Published
August 10, 2026
Last Modified
August 10, 2026

🔗 CVE IDs covered (1)

📋 Description

Multiple vulnerabilities in NASA fprime-gds through 3.4.3 allow an unauthenticated remote attacker to achieve arbitrary code execution on the ground station host and inject arbitrary commands to connected spacecraft. The Flask application in src/fprime_gds/flask/app.py applies no authentication to any endpoint.

🔗 References (6)