CVE-2026-72577EPSS p55.0%
CVE-2026-72577CVE-2026-72577
Description
Multiple vulnerabilities in NASA fprime-gds through 3.4.3 allow an unauthenticated remote attacker to achieve arbitrary code execution on the ground station host and inject arbitrary commands to connected spacecraft. The Flask application in src/fprime_gds/flask/app.py applies no authentication to any endpoint.
Scoring
| CVSS | 9.8 () |
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 0.85% probability of exploitation · percentile 55.0% · 2026-08-11T12:00:17Z |
| Last modified | 2026-08-10 |