Product
Ground-station versions prior to 0.8.0 are susceptible to an authentication bypass vulnerability in the setup.restore command, allowing unauthenticated attackers to execute arbitrary SQL, inject admin users, and achieve full application takeover.