PT-2026-78443 · Unknown · Ground Station

CVE-2026-53452

·

Published

2026-08-19

·

Updated

2026-08-25

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Ground Station versions prior to 0.4.13
Description An unauthenticated Socket.IO command configure-sdr accepts a recordingPath for the sigmf-playback SDR. The system stores this path without validation in backend/handlers/entities/sdr.py, and backend/hardware/sigmfprobe.py opens the path without enforcing containment. An attacker can use an absolute path or parent-directory escape ending in .sigmf-meta to have the file parsed as JSON and returned via the get-sdr-parameters flow. This allows the disclosure of contents outside the backend/data/recordings directory without authentication, provided the target metadata file is readable JSON and has a corresponding .sigmf-data sibling file.
Recommendations Update Ground Station to version 0.4.13.

Exploit

Fix

Information Disclosure

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-53452
GHSA-G344-JQCX-CR7Q

Affected Products

Ground Station