DOM-based cross-site scripting through the publicly exposed Cesium Sandcastle shared-code feature

Disclosed by
iaramsri
Summary by iaramsri

Summary

The publicly accessible Cesium Sandcastle application hosted on gpm.nasa.gov accepted attacker-controlled JavaScript through the #c= URL fragment.

When a crafted Sandcastle URL was opened, the application decoded and decompressed the supplied fragment and automatically executed the resulting JavaScript inside a same-origin iframe.

Because the execution iframe was not sandboxed, the injected JavaScript executed within the security context of:

https://gpm.nasa.gov

No authentication was required, and no additional user interaction was necessary after opening the crafted URL.

Researcher: Itthidej Aramsri
Program: NASA - Vulnerability Disclosure Program via Bugcrowd
Vulnerability: DOM-based cross-site scripting through the publicly exposed Cesium Sandcastle shared-code feature
Status: Resolved
Resolved: August 27, 2026

Activity