Executive brief
NASA's AMMOS Instrument Toolkit (AIT-Core), a software suite used for managing satellite and CubeSat missions, contains a vulnerability in its data capture component. An unauthenticated attacker can remotely bypass security restrictions to write or append data to any file on the host system. This could lead to system crashes, data corruption, or potentially full system takeover if the attacker modifies critical scripts or executable files.
Technical details
A path traversal vulnerability exists in the Binary Stream Capture (BSC) component of AIT-Core due to insufficient validation of path-related fields in the `StreamCaptureManagerServer` unauthenticated HTTP API. The `_add_logger_by_name` handler blindly trusts form fields such as `log_dir_path` and `path`, passing them to `os.path.join()`. An attacker can provide absolute paths or traversal sequences to escape the configured log directory. By directing the BSC process to log to sensitive files (e.g., Python scripts or system configurations), an attacker can append arbitrary data, leading to data corruption or Remote Code Execution (RCE). The vulnerability can be exploited directly via network requests or indirectly via Cross-Site Request Forgery (CSRF) if a user in the local network visits a malicious website. Fixed in versions 2.6.1 and 3.1.1.
Affected products
- NASA-AMMOS AIT-Core 2.x before 2.6.1, 3.1.0
Timeline
- 2026-05-19: patched: Versions 2.6.1 and 3.1.1 released
- 2026-07-21: advisory: NVD publication date