Summary by iaramsri
Summary
The publicly accessible Cesium Sandcastle application hosted on gpm.nasa.gov accepted attacker-controlled JavaScript through the #c= URL fragment.
When a crafted Sandcastle URL was opened, the application decoded and decompressed the supplied fragment and automatically executed the resulting JavaScript inside a same-origin iframe.
Because the execution iframe was not sandboxed, the injected JavaScript executed within the security context of:
https://gpm.nasa.gov
No authentication was required, and no additional user interaction was necessary after opening the crafted URL.
Researcher: Itthidej Aramsri
Program: NASA - Vulnerability Disclosure Program via Bugcrowd
Vulnerability: DOM-based cross-site scripting through the publicly exposed Cesium Sandcastle shared-code feature
Status: Resolved
Resolved: August 27, 2026