PT-2026-103777 · Unknown · Ground Station
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
ground-station versions prior to 0.8.0
Description
An authentication bypass exists in the
setup.restore command during the first-run setup mode. Unauthenticated attackers can use Socket.IO to invoke this command and execute arbitrary SQL, enabling them to create administrator users and forge session tokens. This allows for complete application takeover by authenticating as an administrator without providing credentials.Recommendations
Update ground-station to version 0.8.0 or later.
Exploit
Fix
Missing Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ground Station