Remote Code Execution Vulnerability in Ground Station by SGoudelis
CVE-2026-53451
What is CVE-2026-53451?
Ground Station, a suite for satellite tracking and SDR reception, contains a vulnerability discovered in versions before 0.4.13. An unauthenticated command allows attackers to insert file paths that can lead to unauthorized writing of files outside of designated directories. Specifically, a malicious user could leverage the 'save-waterfall-snapshot' operation to manipulate input and create a logging configuration file. By executing this file during a service restart, the attacker could gain elevated privileges, execute arbitrary code, or induce a persistent crash of the service. This vulnerability poses significant risks to the integrity and availability of the Ground Station platform, underscoring the need for timely updates to version 0.4.13 or later.
Affected Version(s)
ground-station < 0.4.13
