CVE-2026-53452
published 2026-08-19CVE-2026-53452: Ground Station is a browser-based suite for satellite tracking, SDR reception, hardware control, and telemetry decoding. Prior to version 0.4.13, the…
PriorityP432medium5.3CVSS 3.1
AVNACLPRNUINSUCLINAN
EPSS
0.38%
31.6th percentile
Ground Station is a browser-based suite for satellite tracking, SDR reception, hardware control, and telemetry decoding. Prior to version 0.4.13, the unauthenticated configure-sdr Socket.IO command accepts a recordingPath for the sigmf-playback SDR and backend/handlers/entities/sdr.py stores it without validation before backend/hardware/sigmfprobe.py opens the path without enforcing containment. An absolute path or parent-directory escape ending in .sigmf-meta is parsed as JSON and returned in reply["data"]["metadata"] by the get-sdr-parameters flow. Exploitation requires the metadata file to be readable JSON and to have a sibling .sigmf-data file, but it can disclose contents outside backend/data/recordings without authentication. This issue is fixed in version 0.4.13.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| sgoudelis | ground-station | < 0.4.13 | 0.4.13 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No advisories linked to this vulnerability.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://github.com/sgoudelis/ground-station/commit/5649905f1021155933463a54a76030924adffb9dhttps://github.com/sgoudelis/ground-station/releases/tag/v0.4.13https://github.com/sgoudelis/ground-station/security/advisories/GHSA-g344-jqcx-cr7qhttps://github.com/sgoudelis/ground-station/security/advisories/GHSA-g344-jqcx-cr7q
2026-08-19
Published