Security: NASA-AMMOS/AIT-Core
Security
No security policy detected
This project has not set up a SECURITY.md file yet.
Report a vulnerability-
Unauthenticated ZeroMQ command/telemetry bus in AIT-Core allows remote spacecraft command injection and telemetry exfiltration (CWE-306)GHSA-ccw5-g774-3683 published
Sep 16, 2026 by EmilyPascuaCritical -
AIT-Core OpenMCT plugin: unauthenticated WebSocket `unsubscribe` with no argument crashes the connection handler (DoS)GHSA-rgwv-x7h5-f7j3 published
Sep 16, 2026 by EmilyPascuaModerate -
Format-string memory exhaustion in BSC capture manager via unvalidated file_name_patternGHSA-fjr5-6w4j-47xf published
Sep 15, 2026 by EmilyPascuaHigh -
Cross-Site WebSocket Hijacking and Missing Authentication Exposes Live Spacecraft TelemetryGHSA-7h55-xp8q-247v published
Sep 16, 2026 by EmilyPascuaModerate -
AIT-Core Tlmdict CSV Path TraversalGHSA-93gm-4cqq-j774 published
Sep 15, 2026 by EmilyPascuaModerate -
Path traversal resulting in arbitrary file append (can be triggered over the network by unauthenticated attacker)GHSA-p462-prxw-mjx4 published
May 19, 2026 by EmilyPascuaCritical
Learn more about advisories related to NASA-AMMOS/AIT-Core in the GitHub Advisory Database