Search
Find a vulnerability
Search criteria
6 vulnerabilities by sgoudelis
CVE-2026-103244 (GCVE-0-2026-103244)
Vulnerability from nvd – Published: 2026-10-01 10:41 – Updated: 2026-10-01 13:25
VLAI
EPSS
VEX
Title
ground-station before 0.8.0 Authentication Bypass via setup.restore
Summary
ground-station versions before 0.8.0 contain an authentication bypass vulnerability in the setup.restore command that allows unauthenticated attackers to execute arbitrary SQL during first-run setup mode. Attackers can invoke setup.restore via Socket.IO to plant admin users and forged session tokens, then authenticate as administrator without credentials for complete application takeover.
Severity
9.8 (Critical)
SSVC
Exploitation: poc
Automatable: yes
Technical Impact: total
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-10-01 13:24 UTC
CWE
- CWE-306 - Missing Authentication for Critical Function
Assigner
References
3 references
| URL | Tags |
|---|---|
| https://github.com/sgoudelis/ground-station/secur… | vendor-advisory |
| https://github.com/sgoudelis/ground-station/commi… | patch |
| https://www.vulncheck.com/advisories/ground-stati… | third-party-advisory |
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| sgoudelis | ground-station |
Affected:
0 , < 0.8.0
(semver)
|
Date Public
2026-09-14 00:00
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-103244",
"options": [
{
"Exploitation": "poc"
},
{
"Automatable": "yes"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-10-01T13:24:35.274672Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-10-01T13:25:20.227Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"references": [
{
"tags": [
"exploit"
],
"url": "https://github.com/sgoudelis/ground-station/security/advisories/GHSA-3mqj-q84c-crjq"
}
],
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "ground-station",
"vendor": "sgoudelis",
"versions": [
{
"lessThan": "0.8.0",
"status": "affected",
"version": "0",
"versionType": "semver"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "reporter",
"value": "0x4r35"
}
],
"datePublic": "2026-09-14T00:00:00.000Z",
"descriptions": [
{
"lang": "en",
"value": "ground-station versions before 0.8.0 contain an authentication bypass vulnerability in the setup.restore command that allows unauthenticated attackers to execute arbitrary SQL during first-run setup mode. Attackers can invoke setup.restore via Socket.IO to plant admin users and forged session tokens, then authenticate as administrator without credentials for complete application takeover."
}
],
"metrics": [
{
"cvssV4_0": {
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "NETWORK",
"baseScore": 9.3,
"baseSeverity": "CRITICAL",
"privilegesRequired": "NONE",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "HIGH",
"vulnConfidentialityImpact": "HIGH",
"vulnIntegrityImpact": "HIGH"
},
"format": "CVSS"
},
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 9.8,
"baseSeverity": "CRITICAL",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"format": "CVSS"
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-306",
"description": "Missing Authentication for Critical Function",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-01T10:41:51.859Z",
"orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"shortName": "VulnCheck"
},
"references": [
{
"name": "GitHub Security Advisory (GHSA-3mqj-q84c-crjq)",
"tags": [
"vendor-advisory"
],
"url": "https://github.com/sgoudelis/ground-station/security/advisories/GHSA-3mqj-q84c-crjq"
},
{
"name": "Patch Commit",
"tags": [
"patch"
],
"url": "https://github.com/sgoudelis/ground-station/commit/940df2128e57fa779d0ddee2d9726bd829fc61e1"
},
{
"name": "VulnCheck Advisory: ground-station before 0.8.0 Authentication Bypass via setup.restore",
"tags": [
"third-party-advisory"
],
"url": "https://www.vulncheck.com/advisories/ground-station-before-0.8.0-authentication-bypass-via-setup-restore"
}
],
"title": "ground-station before 0.8.0 Authentication Bypass via setup.restore",
"x_generator": {
"engine": "vulncheck-endgame"
}
}
},
"cveMetadata": {
"assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"assignerShortName": "VulnCheck",
"cveId": "CVE-2026-103244",
"datePublished": "2026-10-01T10:41:51.859Z",
"dateReserved": "2026-09-30T10:52:32.248Z",
"dateUpdated": "2026-10-01T13:25:20.227Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-53452 (GCVE-0-2026-53452)
Vulnerability from nvd – Published: 2026-08-19 14:44 – Updated: 2026-08-25 02:05
VLAI
EPSS
VEX
Title
Ground Station: Unauthenticated out-of-containment file read via `sigmfplayback` `recordingPath`
Summary
Ground Station is a browser-based suite for satellite tracking, SDR reception, hardware control, and telemetry decoding. Prior to version 0.4.13, the unauthenticated configure-sdr Socket.IO command accepts a recordingPath for the sigmf-playback SDR and backend/handlers/entities/sdr.py stores it without validation before backend/hardware/sigmfprobe.py opens the path without enforcing containment. An absolute path or parent-directory escape ending in .sigmf-meta is parsed as JSON and returned in reply["data"]["metadata"] by the get-sdr-parameters flow. Exploitation requires the metadata file to be readable JSON and to have a sibling .sigmf-data file, but it can disclose contents outside backend/data/recordings without authentication. This issue is fixed in version 0.4.13.
Severity
5.3 (Medium)
SSVC
Exploitation: poc
Automatable: yes
Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-08-25 02:04 UTC
CWE
Assigner
References
3 references
| URL | Tags |
|---|---|
| https://github.com/sgoudelis/ground-station/secur… | x_refsource_CONFIRM |
| https://github.com/sgoudelis/ground-station/commi… | x_refsource_MISC |
| https://github.com/sgoudelis/ground-station/relea… | x_refsource_MISC |
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| sgoudelis | ground-station |
Affected:
< 0.4.13
|
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-53452",
"options": [
{
"Exploitation": "poc"
},
{
"Automatable": "yes"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-08-25T02:04:34.509684Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-08-25T02:05:30.820Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"references": [
{
"tags": [
"exploit"
],
"url": "https://github.com/sgoudelis/ground-station/security/advisories/GHSA-g344-jqcx-cr7q"
}
],
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"product": "ground-station",
"vendor": "sgoudelis",
"versions": [
{
"status": "affected",
"version": "\u003c 0.4.13"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Ground Station is a browser-based suite for satellite tracking, SDR reception, hardware control, and telemetry decoding. Prior to version 0.4.13, the unauthenticated configure-sdr Socket.IO command accepts a recordingPath for the sigmf-playback SDR and backend/handlers/entities/sdr.py stores it without validation before backend/hardware/sigmfprobe.py opens the path without enforcing containment. An absolute path or parent-directory escape ending in .sigmf-meta is parsed as JSON and returned in reply[\"data\"][\"metadata\"] by the get-sdr-parameters flow. Exploitation requires the metadata file to be readable JSON and to have a sibling .sigmf-data file, but it can disclose contents outside backend/data/recordings without authentication. This issue is fixed in version 0.4.13."
}
],
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "NONE",
"baseScore": 5.3,
"baseSeverity": "MEDIUM",
"confidentialityImpact": "LOW",
"integrityImpact": "NONE",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
"version": "3.1"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-22",
"description": "CWE-22: Improper Limitation of a Pathname to a Restricted Directory (\u0027Path Traversal\u0027)",
"lang": "en",
"type": "CWE"
}
]
},
{
"descriptions": [
{
"cweId": "CWE-200",
"description": "CWE-200: Exposure of Sensitive Information to an Unauthorized Actor",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T14:44:20.658Z",
"orgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
"shortName": "GitHub_M"
},
"references": [
{
"name": "https://github.com/sgoudelis/ground-station/security/advisories/GHSA-g344-jqcx-cr7q",
"tags": [
"x_refsource_CONFIRM"
],
"url": "https://github.com/sgoudelis/ground-station/security/advisories/GHSA-g344-jqcx-cr7q"
},
{
"name": "https://github.com/sgoudelis/ground-station/commit/5649905f1021155933463a54a76030924adffb9d",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/sgoudelis/ground-station/commit/5649905f1021155933463a54a76030924adffb9d"
},
{
"name": "https://github.com/sgoudelis/ground-station/releases/tag/v0.4.13",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/sgoudelis/ground-station/releases/tag/v0.4.13"
}
],
"source": {
"advisory": "GHSA-g344-jqcx-cr7q",
"discovery": "UNKNOWN"
},
"title": "Ground Station: Unauthenticated out-of-containment file read via `sigmfplayback` `recordingPath`"
}
},
"cveMetadata": {
"assignerOrgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
"assignerShortName": "GitHub_M",
"cveId": "CVE-2026-53452",
"datePublished": "2026-08-19T14:44:20.658Z",
"dateReserved": "2026-06-09T16:31:21.494Z",
"dateUpdated": "2026-08-25T02:05:30.820Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-53451 (GCVE-0-2026-53451)
Vulnerability from nvd – Published: 2026-08-19 14:45 – Updated: 2026-08-21 19:32
VLAI
EPSS
VEX
Title
Ground Station: Unauthenticated arbitrary file write (path traversal) in save-waterfall-snapshot leads to remote code execution
Summary
Ground Station is a browser-based suite for satellite tracking, SDR reception, hardware control, and telemetry decoding. Prior to version 0.4.13, the unauthenticated save-waterfall-snapshot Socket.IO command passes attacker-controlled snapshotName input from backend/handlers/entities/sdr.py to backend/server/snapshots.py, where os.path.join permits an absolute path or parent-directory traversal and writes attacker-controlled base64-decoded bytes outside backend/data/snapshots. An attacker can write a logging YAML file containing a logging.config.dictConfig callable factory, use the unauthenticated update-app-config operation to set log_config to that file, and invoke restart_service. During restart, backend/common/logger.py passes the YAML through resolve_log_config_path(), yaml.safe_load(), and logging.config.dictConfig(), which executes the factory with service privileges and can also cause a persistent crash loop. This issue is fixed in version 0.4.13.
Severity
9.8 (Critical)
SSVC
Exploitation: poc
Automatable: yes
Technical Impact: total
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-08-21 19:32 UTC
CWE
Assigner
References
3 references
| URL | Tags |
|---|---|
| https://github.com/sgoudelis/ground-station/secur… | x_refsource_CONFIRM |
| https://github.com/sgoudelis/ground-station/commi… | x_refsource_MISC |
| https://github.com/sgoudelis/ground-station/relea… | x_refsource_MISC |
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| sgoudelis | ground-station |
Affected:
< 0.4.13
|
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-53451",
"options": [
{
"Exploitation": "poc"
},
{
"Automatable": "yes"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-08-21T19:32:12.690717Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-08-21T19:32:38.317Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"references": [
{
"tags": [
"exploit"
],
"url": "https://github.com/sgoudelis/ground-station/security/advisories/GHSA-q35x-w3h6-36w8"
}
],
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"product": "ground-station",
"vendor": "sgoudelis",
"versions": [
{
"status": "affected",
"version": "\u003c 0.4.13"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Ground Station is a browser-based suite for satellite tracking, SDR reception, hardware control, and telemetry decoding. Prior to version 0.4.13, the unauthenticated save-waterfall-snapshot Socket.IO command passes attacker-controlled snapshotName input from backend/handlers/entities/sdr.py to backend/server/snapshots.py, where os.path.join permits an absolute path or parent-directory traversal and writes attacker-controlled base64-decoded bytes outside backend/data/snapshots. An attacker can write a logging YAML file containing a logging.config.dictConfig callable factory, use the unauthenticated update-app-config operation to set log_config to that file, and invoke restart_service. During restart, backend/common/logger.py passes the YAML through resolve_log_config_path(), yaml.safe_load(), and logging.config.dictConfig(), which executes the factory with service privileges and can also cause a persistent crash loop. This issue is fixed in version 0.4.13."
}
],
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 9.8,
"baseSeverity": "CRITICAL",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-22",
"description": "CWE-22: Improper Limitation of a Pathname to a Restricted Directory (\u0027Path Traversal\u0027)",
"lang": "en",
"type": "CWE"
}
]
},
{
"descriptions": [
{
"cweId": "CWE-73",
"description": "CWE-73: External Control of File Name or Path",
"lang": "en",
"type": "CWE"
}
]
},
{
"descriptions": [
{
"cweId": "CWE-94",
"description": "CWE-94: Improper Control of Generation of Code (\u0027Code Injection\u0027)",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T14:45:23.951Z",
"orgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
"shortName": "GitHub_M"
},
"references": [
{
"name": "https://github.com/sgoudelis/ground-station/security/advisories/GHSA-q35x-w3h6-36w8",
"tags": [
"x_refsource_CONFIRM"
],
"url": "https://github.com/sgoudelis/ground-station/security/advisories/GHSA-q35x-w3h6-36w8"
},
{
"name": "https://github.com/sgoudelis/ground-station/commit/5649905f1021155933463a54a76030924adffb9d",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/sgoudelis/ground-station/commit/5649905f1021155933463a54a76030924adffb9d"
},
{
"name": "https://github.com/sgoudelis/ground-station/releases/tag/v0.4.13",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/sgoudelis/ground-station/releases/tag/v0.4.13"
}
],
"source": {
"advisory": "GHSA-q35x-w3h6-36w8",
"discovery": "UNKNOWN"
},
"title": "Ground Station: Unauthenticated arbitrary file write (path traversal) in save-waterfall-snapshot leads to remote code execution"
}
},
"cveMetadata": {
"assignerOrgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
"assignerShortName": "GitHub_M",
"cveId": "CVE-2026-53451",
"datePublished": "2026-08-19T14:45:23.951Z",
"dateReserved": "2026-06-09T16:31:21.494Z",
"dateUpdated": "2026-08-21T19:32:38.317Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-103244 (GCVE-0-2026-103244)
Vulnerability from cvelistv5 – Published: 2026-10-01 10:41 – Updated: 2026-10-01 13:25
VLAI
EPSS
VEX
Title
ground-station before 0.8.0 Authentication Bypass via setup.restore
Summary
ground-station versions before 0.8.0 contain an authentication bypass vulnerability in the setup.restore command that allows unauthenticated attackers to execute arbitrary SQL during first-run setup mode. Attackers can invoke setup.restore via Socket.IO to plant admin users and forged session tokens, then authenticate as administrator without credentials for complete application takeover.
Severity
9.8 (Critical)
SSVC
Exploitation: poc
Automatable: yes
Technical Impact: total
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-10-01 13:24 UTC
CWE
- CWE-306 - Missing Authentication for Critical Function
Assigner
References
3 references
| URL | Tags |
|---|---|
| https://github.com/sgoudelis/ground-station/secur… | vendor-advisory |
| https://github.com/sgoudelis/ground-station/commi… | patch |
| https://www.vulncheck.com/advisories/ground-stati… | third-party-advisory |
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| sgoudelis | ground-station |
Affected:
0 , < 0.8.0
(semver)
|
Date Public
2026-09-14 00:00
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-103244",
"options": [
{
"Exploitation": "poc"
},
{
"Automatable": "yes"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-10-01T13:24:35.274672Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-10-01T13:25:20.227Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"references": [
{
"tags": [
"exploit"
],
"url": "https://github.com/sgoudelis/ground-station/security/advisories/GHSA-3mqj-q84c-crjq"
}
],
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "ground-station",
"vendor": "sgoudelis",
"versions": [
{
"lessThan": "0.8.0",
"status": "affected",
"version": "0",
"versionType": "semver"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "reporter",
"value": "0x4r35"
}
],
"datePublic": "2026-09-14T00:00:00.000Z",
"descriptions": [
{
"lang": "en",
"value": "ground-station versions before 0.8.0 contain an authentication bypass vulnerability in the setup.restore command that allows unauthenticated attackers to execute arbitrary SQL during first-run setup mode. Attackers can invoke setup.restore via Socket.IO to plant admin users and forged session tokens, then authenticate as administrator without credentials for complete application takeover."
}
],
"metrics": [
{
"cvssV4_0": {
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "NETWORK",
"baseScore": 9.3,
"baseSeverity": "CRITICAL",
"privilegesRequired": "NONE",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "HIGH",
"vulnConfidentialityImpact": "HIGH",
"vulnIntegrityImpact": "HIGH"
},
"format": "CVSS"
},
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 9.8,
"baseSeverity": "CRITICAL",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"format": "CVSS"
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-306",
"description": "Missing Authentication for Critical Function",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-01T10:41:51.859Z",
"orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"shortName": "VulnCheck"
},
"references": [
{
"name": "GitHub Security Advisory (GHSA-3mqj-q84c-crjq)",
"tags": [
"vendor-advisory"
],
"url": "https://github.com/sgoudelis/ground-station/security/advisories/GHSA-3mqj-q84c-crjq"
},
{
"name": "Patch Commit",
"tags": [
"patch"
],
"url": "https://github.com/sgoudelis/ground-station/commit/940df2128e57fa779d0ddee2d9726bd829fc61e1"
},
{
"name": "VulnCheck Advisory: ground-station before 0.8.0 Authentication Bypass via setup.restore",
"tags": [
"third-party-advisory"
],
"url": "https://www.vulncheck.com/advisories/ground-station-before-0.8.0-authentication-bypass-via-setup-restore"
}
],
"title": "ground-station before 0.8.0 Authentication Bypass via setup.restore",
"x_generator": {
"engine": "vulncheck-endgame"
}
}
},
"cveMetadata": {
"assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"assignerShortName": "VulnCheck",
"cveId": "CVE-2026-103244",
"datePublished": "2026-10-01T10:41:51.859Z",
"dateReserved": "2026-09-30T10:52:32.248Z",
"dateUpdated": "2026-10-01T13:25:20.227Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-53451 (GCVE-0-2026-53451)
Vulnerability from cvelistv5 – Published: 2026-08-19 14:45 – Updated: 2026-08-21 19:32
VLAI
EPSS
VEX
Title
Ground Station: Unauthenticated arbitrary file write (path traversal) in save-waterfall-snapshot leads to remote code execution
Summary
Ground Station is a browser-based suite for satellite tracking, SDR reception, hardware control, and telemetry decoding. Prior to version 0.4.13, the unauthenticated save-waterfall-snapshot Socket.IO command passes attacker-controlled snapshotName input from backend/handlers/entities/sdr.py to backend/server/snapshots.py, where os.path.join permits an absolute path or parent-directory traversal and writes attacker-controlled base64-decoded bytes outside backend/data/snapshots. An attacker can write a logging YAML file containing a logging.config.dictConfig callable factory, use the unauthenticated update-app-config operation to set log_config to that file, and invoke restart_service. During restart, backend/common/logger.py passes the YAML through resolve_log_config_path(), yaml.safe_load(), and logging.config.dictConfig(), which executes the factory with service privileges and can also cause a persistent crash loop. This issue is fixed in version 0.4.13.
Severity
9.8 (Critical)
SSVC
Exploitation: poc
Automatable: yes
Technical Impact: total
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-08-21 19:32 UTC
CWE
Assigner
References
3 references
| URL | Tags |
|---|---|
| https://github.com/sgoudelis/ground-station/secur… | x_refsource_CONFIRM |
| https://github.com/sgoudelis/ground-station/commi… | x_refsource_MISC |
| https://github.com/sgoudelis/ground-station/relea… | x_refsource_MISC |
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| sgoudelis | ground-station |
Affected:
< 0.4.13
|
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-53451",
"options": [
{
"Exploitation": "poc"
},
{
"Automatable": "yes"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-08-21T19:32:12.690717Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-08-21T19:32:38.317Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"references": [
{
"tags": [
"exploit"
],
"url": "https://github.com/sgoudelis/ground-station/security/advisories/GHSA-q35x-w3h6-36w8"
}
],
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"product": "ground-station",
"vendor": "sgoudelis",
"versions": [
{
"status": "affected",
"version": "\u003c 0.4.13"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Ground Station is a browser-based suite for satellite tracking, SDR reception, hardware control, and telemetry decoding. Prior to version 0.4.13, the unauthenticated save-waterfall-snapshot Socket.IO command passes attacker-controlled snapshotName input from backend/handlers/entities/sdr.py to backend/server/snapshots.py, where os.path.join permits an absolute path or parent-directory traversal and writes attacker-controlled base64-decoded bytes outside backend/data/snapshots. An attacker can write a logging YAML file containing a logging.config.dictConfig callable factory, use the unauthenticated update-app-config operation to set log_config to that file, and invoke restart_service. During restart, backend/common/logger.py passes the YAML through resolve_log_config_path(), yaml.safe_load(), and logging.config.dictConfig(), which executes the factory with service privileges and can also cause a persistent crash loop. This issue is fixed in version 0.4.13."
}
],
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 9.8,
"baseSeverity": "CRITICAL",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-22",
"description": "CWE-22: Improper Limitation of a Pathname to a Restricted Directory (\u0027Path Traversal\u0027)",
"lang": "en",
"type": "CWE"
}
]
},
{
"descriptions": [
{
"cweId": "CWE-73",
"description": "CWE-73: External Control of File Name or Path",
"lang": "en",
"type": "CWE"
}
]
},
{
"descriptions": [
{
"cweId": "CWE-94",
"description": "CWE-94: Improper Control of Generation of Code (\u0027Code Injection\u0027)",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T14:45:23.951Z",
"orgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
"shortName": "GitHub_M"
},
"references": [
{
"name": "https://github.com/sgoudelis/ground-station/security/advisories/GHSA-q35x-w3h6-36w8",
"tags": [
"x_refsource_CONFIRM"
],
"url": "https://github.com/sgoudelis/ground-station/security/advisories/GHSA-q35x-w3h6-36w8"
},
{
"name": "https://github.com/sgoudelis/ground-station/commit/5649905f1021155933463a54a76030924adffb9d",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/sgoudelis/ground-station/commit/5649905f1021155933463a54a76030924adffb9d"
},
{
"name": "https://github.com/sgoudelis/ground-station/releases/tag/v0.4.13",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/sgoudelis/ground-station/releases/tag/v0.4.13"
}
],
"source": {
"advisory": "GHSA-q35x-w3h6-36w8",
"discovery": "UNKNOWN"
},
"title": "Ground Station: Unauthenticated arbitrary file write (path traversal) in save-waterfall-snapshot leads to remote code execution"
}
},
"cveMetadata": {
"assignerOrgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
"assignerShortName": "GitHub_M",
"cveId": "CVE-2026-53451",
"datePublished": "2026-08-19T14:45:23.951Z",
"dateReserved": "2026-06-09T16:31:21.494Z",
"dateUpdated": "2026-08-21T19:32:38.317Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-53452 (GCVE-0-2026-53452)
Vulnerability from cvelistv5 – Published: 2026-08-19 14:44 – Updated: 2026-08-25 02:05
VLAI
EPSS
VEX
Title
Ground Station: Unauthenticated out-of-containment file read via `sigmfplayback` `recordingPath`
Summary
Ground Station is a browser-based suite for satellite tracking, SDR reception, hardware control, and telemetry decoding. Prior to version 0.4.13, the unauthenticated configure-sdr Socket.IO command accepts a recordingPath for the sigmf-playback SDR and backend/handlers/entities/sdr.py stores it without validation before backend/hardware/sigmfprobe.py opens the path without enforcing containment. An absolute path or parent-directory escape ending in .sigmf-meta is parsed as JSON and returned in reply["data"]["metadata"] by the get-sdr-parameters flow. Exploitation requires the metadata file to be readable JSON and to have a sibling .sigmf-data file, but it can disclose contents outside backend/data/recordings without authentication. This issue is fixed in version 0.4.13.
Severity
5.3 (Medium)
SSVC
Exploitation: poc
Automatable: yes
Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-08-25 02:04 UTC
CWE
Assigner
References
3 references
| URL | Tags |
|---|---|
| https://github.com/sgoudelis/ground-station/secur… | x_refsource_CONFIRM |
| https://github.com/sgoudelis/ground-station/commi… | x_refsource_MISC |
| https://github.com/sgoudelis/ground-station/relea… | x_refsource_MISC |
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| sgoudelis | ground-station |
Affected:
< 0.4.13
|
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-53452",
"options": [
{
"Exploitation": "poc"
},
{
"Automatable": "yes"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-08-25T02:04:34.509684Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-08-25T02:05:30.820Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"references": [
{
"tags": [
"exploit"
],
"url": "https://github.com/sgoudelis/ground-station/security/advisories/GHSA-g344-jqcx-cr7q"
}
],
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"product": "ground-station",
"vendor": "sgoudelis",
"versions": [
{
"status": "affected",
"version": "\u003c 0.4.13"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Ground Station is a browser-based suite for satellite tracking, SDR reception, hardware control, and telemetry decoding. Prior to version 0.4.13, the unauthenticated configure-sdr Socket.IO command accepts a recordingPath for the sigmf-playback SDR and backend/handlers/entities/sdr.py stores it without validation before backend/hardware/sigmfprobe.py opens the path without enforcing containment. An absolute path or parent-directory escape ending in .sigmf-meta is parsed as JSON and returned in reply[\"data\"][\"metadata\"] by the get-sdr-parameters flow. Exploitation requires the metadata file to be readable JSON and to have a sibling .sigmf-data file, but it can disclose contents outside backend/data/recordings without authentication. This issue is fixed in version 0.4.13."
}
],
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "NONE",
"baseScore": 5.3,
"baseSeverity": "MEDIUM",
"confidentialityImpact": "LOW",
"integrityImpact": "NONE",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
"version": "3.1"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-22",
"description": "CWE-22: Improper Limitation of a Pathname to a Restricted Directory (\u0027Path Traversal\u0027)",
"lang": "en",
"type": "CWE"
}
]
},
{
"descriptions": [
{
"cweId": "CWE-200",
"description": "CWE-200: Exposure of Sensitive Information to an Unauthorized Actor",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T14:44:20.658Z",
"orgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
"shortName": "GitHub_M"
},
"references": [
{
"name": "https://github.com/sgoudelis/ground-station/security/advisories/GHSA-g344-jqcx-cr7q",
"tags": [
"x_refsource_CONFIRM"
],
"url": "https://github.com/sgoudelis/ground-station/security/advisories/GHSA-g344-jqcx-cr7q"
},
{
"name": "https://github.com/sgoudelis/ground-station/commit/5649905f1021155933463a54a76030924adffb9d",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/sgoudelis/ground-station/commit/5649905f1021155933463a54a76030924adffb9d"
},
{
"name": "https://github.com/sgoudelis/ground-station/releases/tag/v0.4.13",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/sgoudelis/ground-station/releases/tag/v0.4.13"
}
],
"source": {
"advisory": "GHSA-g344-jqcx-cr7q",
"discovery": "UNKNOWN"
},
"title": "Ground Station: Unauthenticated out-of-containment file read via `sigmfplayback` `recordingPath`"
}
},
"cveMetadata": {
"assignerOrgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
"assignerShortName": "GitHub_M",
"cveId": "CVE-2026-53452",
"datePublished": "2026-08-19T14:44:20.658Z",
"dateReserved": "2026-06-09T16:31:21.494Z",
"dateUpdated": "2026-08-25T02:05:30.820Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}