PT-2026-69461 · Nasa · Fprime-Gds

·

CVE-2026-72577

·

Published

2026-08-10

·

Updated

2026-08-29

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions NASA fprime-gds versions prior to 3.4.4
Description An unauthenticated remote attacker can achieve arbitrary code execution on the ground station host and inject arbitrary commands to connected spacecraft. The Flask application in src/fprime gds/flask/app.py does not apply authentication to any endpoint. Additionally, a path traversal in src/fprime gds/flask/updown.py allows reading and writing arbitrary files outside the upload directory. The application also contains a hardcoded secret key, which enables session forgery. Chaining these issues allows for the complete compromise of the ground data system and any spacecraft under its control.
Recommendations Update to version 3.4.4 or later.

Exploit

Fix

RCE

Missing Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-72577

Affected Products

Fprime-Gds