Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 25 Aug 2026 02:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 21 Aug 2026 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Efstratios Goudelis
Efstratios Goudelis ground Station |
|
| Vendors & Products |
Efstratios Goudelis
Efstratios Goudelis ground Station |
Wed, 19 Aug 2026 15:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Ground Station is a browser-based suite for satellite tracking, SDR reception, hardware control, and telemetry decoding. Prior to version 0.4.13, the unauthenticated configure-sdr Socket.IO command accepts a recordingPath for the sigmf-playback SDR and backend/handlers/entities/sdr.py stores it without validation before backend/hardware/sigmfprobe.py opens the path without enforcing containment. An absolute path or parent-directory escape ending in .sigmf-meta is parsed as JSON and returned in reply["data"]["metadata"] by the get-sdr-parameters flow. Exploitation requires the metadata file to be readable JSON and to have a sibling .sigmf-data file, but it can disclose contents outside backend/data/recordings without authentication. This issue is fixed in version 0.4.13. | |
| Title | Ground Station: Unauthenticated out-of-containment file read via `sigmfplayback` `recordingPath` | |
| Weaknesses | CWE-200 CWE-22 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-08-25T02:05:30.820Z
Reserved: 2026-06-09T16:31:21.494Z
Link: CVE-2026-53452
Updated: 2026-08-25T02:05:26.107Z
Status : Received
Published: 2026-08-19T15:17:10.280
Modified: 2026-08-25T03:16:55.560
Link: CVE-2026-53452
No data.
OpenCVE Enrichment
Updated: 2026-08-21T20:45:03Z