CVE-2026-72579 describes an OS command injection issue in NASA HyperCP, a research tool used to retrieve and process ocean color / remote-sensing data.
During download workflows, response data associated with oceandata.sci.gsfc.nasa.gov can influence local command execution without sufficient sanitization. A network-adjacent attacker able to intercept or spoof those responses may execute arbitrary commands on the researcher's workstation.
The attack path depends on network position and user interaction with download operations, but successful exploitation yields full workstation compromise. Until a patch is available, avoid running HyperCP on untrusted networks and track the official CVE and repository updates.