VYPR
Vendor

Spaceapplications

Products
2
CVEs
14
Across products
14
Status
Private

Products

2

Recent CVEs

14
  • CVE-2026-46562CriJul 16, 2026
    risk 0.64cvss 9.8epss 0.01

    Yamcs is a mission control framework. Prior to 5.12.7, the Nashorn ScriptEngine used to evaluate user-supplied JavaScript algorithm text in yamcs-core/src/main/java/org/yamcs/algorithms/ScriptAlgorithmExecutorFactory.java was constructed without a ClassFilter, so a user with the…

  • CVE-2026-46621CriJul 16, 2026
    risk 0.59cvss 9.1epss 0.01

    Yamcs is a mission control framework. Prior to 5.12.7, the Yamcs script evaluation engine for Python algorithms dynamically compiled and evaluated user-controlled algorithm text using Jython through the JSR-223 ScriptEngine API without enforcing a secure sandbox, so an…

  • CVE-2026-44632CriJul 16, 2026
    risk 0.59cvss 9.1epss 0.01

    Yamcs is a mission control framework. Prior to 5.12.7, a server-side code injection vulnerability existed in the Yamcs algorithm evaluation engine org.yamcs.algorithms.JavaExprAlgorithmExecutionFactory, which dynamically compiled and evaluated user-controlled algorithm text…

  • CVE-2023-45278CriOct 19, 2023
    risk 0.59cvss 9.1epss 0.02

    Directory Traversal vulnerability in the storage functionality of the API in Yamcs 5.8.6 allows attackers to delete arbitrary files via crafted HTTP DELETE request.

  • CVE-2023-45277HigOct 19, 2023
    risk 0.49cvss 7.5epss 0.01

    Yamcs 5.8.6 is vulnerable to directory traversal (issue 1 of 2). The vulnerability is in the storage functionality of the API and allows one to escape the base directory of the buckets, freely navigate system directories, and read arbitrary files.

  • CVE-2026-44596MedJul 16, 2026
    risk 0.45cvss 6.5epss 0.02

    Yamcs is a mission control framework. Prior to 5.12.7, the authentication endpoint POST /auth/token in yamcs-core, handled by yamcs-core/src/main/java/org/yamcs/http/auth/AuthHandler.java, lacked any rate limiting, account lockout, or failed-attempt throttling, so an…

  • CVE-2023-47311MedNov 20, 2023
    risk 0.40cvss 6.1epss 0.00

    An issue in Yamcs 5.8.6 allows attackers to send aribitrary telelcommands in a Command Stack via Clickjacking.

  • CVE-2023-45281MedOct 19, 2023
    risk 0.40cvss 6.1epss 0.00

    An issue in Yamcs 5.8.6 allows attackers to obtain the session cookie via upload of crafted HTML file.

  • CVE-2023-46471MedNov 20, 2023
    risk 0.35cvss 5.4epss 0.01

    Cross Site Scripting vulnerability in Space Applications Services Yamcs v.5.8.6 allows a remote attacker to execute arbitrary code via the text variable scriptContainer of the ScriptViewer.

  • CVE-2023-46470MedNov 20, 2023
    risk 0.35cvss 5.4epss 0.01

    Cross Site Scripting vulnerability in Space Applications Services Yamcs v.5.8.6 allows a remote attacker to execute arbitrary code via crafted telecommand in the timeline view of the ArchiveBrowser.

  • CVE-2023-45280MedOct 19, 2023
    risk 0.35cvss 5.4epss 0.01

    Yamcs 5.8.6 allows XSS (issue 2 of 2). It comes with a Bucket as its primary storage mechanism. Buckets allow for the upload of any file. There's a way to upload an HTML file containing arbitrary JavaScript and then navigate to it. Once the user opens the file, the browser will…

  • CVE-2023-45279MedOct 19, 2023
    risk 0.35cvss 5.4epss 0.00

    Yamcs 5.8.6 allows XSS (issue 1 of 2). It comes with a Bucket as its primary storage mechanism. Buckets allow for the upload of any file. There's a way to upload a display referencing a malicious JavaScript file to the bucket. The user can then open the uploaded display by…

  • CVE-2026-44595MedJul 16, 2026
    risk 0.31cvss 4.3epss 0.01

    Yamcs is a mission control framework. Prior to 5.12.7, the IAM API endpoints listUsers, getUser, listGroups, and getGroup in yamcs-core did not enforce the required SystemPrivilege.ControlAccess check in yamcs-core/src/main/java/org/yamcs/http/api/IamApi.java, so any…

  • CVE-2026-55548MedJul 16, 2026
    risk 0.00cvss 4.3epss 0.00

    Yamcs is a mission control framework. Prior to 5.12.8 and 5.13.2, the PacketsApi.exportPackets endpoint in yamcs-core/src/main/java/org/yamcs/http/api/PacketsApi.java failed to enforce object-level ReadPacket privileges when a request omitted specific packet names: with an empty…