CVE-2026-72577
CRITICAL
NVD
CVSS Score
9.8
Severity
CRITICAL
Published
Aug 10, 2026
Vendor
unknown
Description
Multiple vulnerabilities in NASA fprime-gds through 3.4.3 allow an unauthenticated remote attacker to achieve arbitrary code execution on the ground station host and inject arbitrary commands to connected spacecraft. The Flask application in src/fprime_gds/flask/app.py applies no authentication to any endpoint.