CRITICAL 9.8 NVD
CVE-2026-72577
Multiple vulnerabilities in NASA fprime-gds through 3.4.3 allow an unauthenticated remote attacker to achieve arbitrary code execution on the ground station hos
Multiple vulnerabilities in NASA fprime-gds through 3.4.3 allow an unauthenticated remote attacker to achieve arbitrary code execution on the ground station host and inject arbitrary commands to connected spacecraft. The Flask application in src/fprime_gds/flask/app.py applies no authentication to any endpoint.
References
- https://github.com/nasa/fprime-gds
- https://github.com/nasa/fprime-gds/blob/main/src/fprime_gds/flask/commands.py
- https://github.com/nasa/fprime-gds/blob/main/src/fprime_gds/flask/updown.py
- https://pypi.org/project/fprime-gds/
This critical severity vulnerability with a CVSS score of 9.8 was published on 2026-08-10 via NVD.
Risk Timeline
CVE Disclosed2026-08-10 · -1 days ago
Remediation Resources
vulnfeed aggregates 9095 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.