GHSA-wwmv-hj9m-4mccCriticalCVSS 9.8

ground-station versions before 0.8.0 contain an authentication bypass vulnerability in the setup...

Published
October 1, 2026
Last Modified
October 1, 2026

🔗 CVE IDs covered (1)

📋 Description

ground-station versions before 0.8.0 contain an authentication bypass vulnerability in the setup.restore command that allows unauthenticated attackers to execute arbitrary SQL during first-run setup mode. Attackers can invoke setup.restore via Socket.IO to plant admin users and forged session tokens, then authenticate as administrator without credentials for complete application takeover.

🔗 References (5)