Summary
CVE-2026-53451 is a critical, unauthenticated path traversal vulnerability in Ground Station, an open-source browser-based SDR orchestration platform for satellite tracking and telemetry decoding (sgoudelis/ground-station). The flaw resides in the save-waterfall-snapshot command, which fails to validate user-supplied file paths, allowing an attacker to write arbitrary files to the filesystem — including a malicious logging configuration file that leads to remote code execution when the service restarts. The vulnerability carries a CVSS v3.1 base score of 9.8 (Critical) and requires no authentication or user interaction to exploit.
Technical details
- Root cause: The
save-waterfall-snapshotcommand constructed file paths from user-supplied input without sanitizing directory traversal sequences (e.g.,../) or rejecting absolute paths, allowing writes outside the intended snapshots directory (CWE-22, CWE-73). - Trigger conditions: An unauthenticated attacker sends a crafted
save-waterfall-snapshotrequest containing a path traversal payload, allowing them to write a YAML file to an arbitrary filesystem location. - Escalation to RCE: The attacker-controlled YAML file can define a
logging.config.dictConfigcallable factory. When Ground Station reloads or restarts and processes this logging configuration, the attacker-specified callable is invoked, resulting in arbitrary code execution with the privileges of the Ground Station service (CWE-94). - Attack vector: Network-based, low complexity, no privileges or user interaction required — the vulnerability is remotely and fully exploitable pre-authentication.
- Impact: Full compromise of confidentiality, integrity, and availability of the host running Ground Station, including arbitrary file write and remote code execution with service-level privileges.
Affected software
- Ground Station (
sgoudelis/ground-station) versions prior to 0.4.13
Severity
- CVSS v3.1 Base Score: 9.8 (Critical)
- Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Mitigation and recommended actions
- Immediate: Upgrade Ground Station to version 0.4.13 or later, which introduces centralized path validation (a new
pathguardmodule) that rejects absolute paths and directory-traversal sequences across snapshot-saving and SigMF playback code paths. - If patching is not immediately possible:
- Restrict network access to the Ground Station web interface/API to trusted hosts only (e.g., via firewall rules or VPN), since the vulnerability is exploitable without authentication over the network.
- Run the Ground Station service with the minimum filesystem privileges necessary, limiting the impact of an arbitrary file write.
- Monitor for unexpected files written outside the configured snapshots directory and for unplanned service restarts, which could indicate exploitation attempts.
- Restrict or audit write access to any directories the service can reach, particularly logging configuration paths.

