VYPR
Critical severity9.8NVD Advisory· Published Aug 10, 2026· Updated Aug 10, 2026

CVE-2026-72577

CVE-2026-72577

Description

Multiple vulnerabilities in NASA fprime-gds through 3.4.3 allow an unauthenticated remote attacker to achieve arbitrary code execution on the ground station host and inject arbitrary commands to connected spacecraft. The Flask application in src/fprime_gds/flask/app.py applies no authentication to any endpoint.

Affected products

1

Patches

Vulnerability mechanics

References

3

News mentions

0

No linked articles in our index yet.