Back to Vulnerability Research

CVE-2026-72579

NASA HyperCP OS Command Injection via Spoofed Data Responses

High · CVSS 3.1 7.5Turan SecurityNASA HyperCPCWE-78
Published
August 10, 2026
Affected versions
Main branch
Researchers
Adrian Gaitan
View on CVE.org

CVE-2026-72579 describes an OS command injection issue in NASA HyperCP, a research tool used to retrieve and process ocean color / remote-sensing data.

During download workflows, response data associated with oceandata.sci.gsfc.nasa.gov can influence local command execution without sufficient sanitization. A network-adjacent attacker able to intercept or spoof those responses may execute arbitrary commands on the researcher's workstation.

The attack path depends on network position and user interaction with download operations, but successful exploitation yields full workstation compromise. Until a patch is available, avoid running HyperCP on untrusted networks and track the official CVE and repository updates.