Impact
An OS command injection vulnerability in NASA HyperCP (main branch) allows a network‑adjacent attacker who can intercept or spoof responses from oceandata.sci.gsfc.nasa.gov to execute arbitrary system commands on the researcher's workstation. The flaw occurs when the client processes response headers from the public data server. The attacker can inject unsafe values into those headers, causing the client to invoke system commands via a subprocess call. This results in full code‑execution compromise of the client machine, driven by the underlying CWE‑78 weakness in the OBPGSession.py module.
Affected Systems
NASA HyperCP (main branch). Version information is not specified in the advisory, so all current installations of HyperCP are potentially vulnerable until a fix is applied.
Risk and Exploitability
The CVSS score of 7.5 signals a high‑impact vulnerability. Although EPSS data is not provided, the attack requires a network‑adjacent attacker capable of tampering with HTTP responses. The vulnerability is not listed in CISA’s KEV catalog, but exploitation remains feasible if an attacker can compromise network traffic to the data server. Attackers could leverage this flaw to gain full system compromise on the client’s workstation.
OpenCVE Enrichment