CVE-2026-53452 is a vulnerability in the Ground Station browser-based suite for satellite tracking, SDR reception, hardware control, and telemetry decoding. An unauthenticated configure-sdr Socket.IO command accepts a recordingPath for the sigmf-playback SDR, which can lead to disclosure of contents outside backend/data/recordings without authentication. The issue is fixed in version 0.4.13.
CVE-2026-53451 is a critical vulnerability in the Ground Station browser-based suite for satellite tracking, SDR reception, hardware control, and telemetry decoding. An unauthenticated attacker can exploit this vulnerability to write arbitrary files outside the intended directory, potentially leading to remote code execution. This can be achieved by using the unauthenticated save-waterfall-snapshot Socket [truncated]