Critical severity9.8NVD Advisory· Published Aug 10, 2026· Updated Aug 10, 2026
CVE-2026-72577
CVE-2026-72577
Description
Multiple vulnerabilities in NASA fprime-gds through 3.4.3 allow an unauthenticated remote attacker to achieve arbitrary code execution on the ground station host and inject arbitrary commands to connected spacecraft. The Flask application in src/fprime_gds/flask/app.py applies no authentication to any endpoint.
Affected products
1Patches
Vulnerability mechanics
References
3News mentions
0No linked articles in our index yet.