Executive brief
Ground Station is a browser-based satellite tracking and telemetry decoding application. An unauthenticated attacker can connect to the application's Socket.IO server without credentials, submit a malicious orbital data source URL, and trigger it to issue arbitrary outbound HTTP requests to internal networks or cloud metadata services. The attacker can infer the results through HTTP status codes in error messages, potentially exposing sensitive internal service information or cloud credentials that persist across service restarts.
Technical details
Ground Station versions before 0.6.0 contain an unauthenticated server-side request forgery (SSRF) vulnerability in the orbital-source configuration handling. The root cause is that Socket.IO authentication is disabled and the application accepts unauthenticated data_submission events with submit-orbital-sources actions that store arbitrary URLs in the database without validation (no scheme allowlist, host validation, or rejection of loopback/RFC1918/link-local addresses). An unauthenticated network attacker can persist a malicious URL in the database by connecting to port 7000, then trigger orbital sync via background_task:start to cause the backend to issue requests.get() calls to attacker-chosen destinations in backend/tlesync/source_adapters.py (_fetch_http_3le and _fetch_http_omm). HTTP status codes and error messages are leaked via orbital_sync_state Socket.IO events to all clients, providing an oracle for interpreting responses from internal services and cloud metadata endpoints (e.g., 169.254.169.254). Because the malicious source persists across restarts and re-fires every 24 hours, the attacker achieves durable SSRF without maintaining a connection. The vulnerability is fixed in version 0.6.0 or later.
Affected products
- sgoudelis Ground Station prior to 0.6.0
Timeline
- 2026-08-06: disclosed