openc3
OpenC3 COSMOS
Activity
- Latest release
- 3d ago
- Total releases
- 60
- Cadence
- ~17 days
- Last 12 months
- 20
Reach
- Stars
- 249
Details
- License
- unknown
- First release
- Aug 04, 2023
| Version | Released | |
|---|---|---|
7.4.0
minor
| ||
7.3.0
minor
| ||
7.2.1
patch
| ||
7.2.0
minor
| ||
7.1.1
patch
| ||
6.10.6
patch
3 CVEs
CVE-2026-42088
PYSEC-2026-2245
GHSA-2wvh-87g2-89hr
May 04, 2026
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. Prior to version 7.0.0-rc3, the Script Runner widget allows users to execute Python and Ruby scripts directly from the openc3-COSMOS-script-runner-api container. Because all the docker containers share a network, users can execute specially crafted scripts to bypass the API permissions check and perform administrative actions, including reading and modifying data inside the Redis database, which can be used to read secrets and change COSMOS settings, as well as read and write to the buckets service, which holds configuration, log, and plugin files. These actions are normally only available from the Admin Console or with administrative privileges. Any user with permission to create and run scripts can connect to any service in the docker network. This issue has been patched in version 7.0.0-rc3. Affected versions
0.1.0
5.10.0
5.10.1
5.11.0
5.11.1
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
+ 40 more Show less
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.20.0
5.9.2b0
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.10.5
6.10.6
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
7.0.0rc2
7.0.0rc3
Fixed in
7.0.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-42087
PYSEC-2026-2244
GHSA-v529-vhwc-wfc5
May 04, 2026
9.6
/ 10
Critical
Network
Low
Low
None
Changed
High
High
None
OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. From version 6.7.0 to before version 7.0.0-rc3, a SQL injection vulnerability exists in the Time-Series Database (TSDB) component of COSMOS. The tsdb_lookup function in the cvt_model.rb file directly places user-supplied input into a SQL query without sanitizing the input. As a result, a user can break out of the initial SQL statement and execute arbitrary SQL commands, including deleting data. This issue has been patched in version 7.0.0-rc3. Affected versions
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.10.5
6.10.6
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
+ 3 more Show less
6.9.2
7.0.0rc2
7.0.0rc3
Fixed in
7.0.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-42086
PYSEC-2026-105
GHSA-ffq5-qpvf-xq7x
May 04, 2026
4.6
/ 10
Medium
Network
Low
Low
Required
Unchanged
Low
Low
None
OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. Prior to version 7.0.0, the Command Sender UI uses an unsafe eval() function on array-like command parameters, which allows a user-supplied payload to execute in the browser when sending a command. This creates a self-XSS risk because an attacker can trigger their own script execution in the victim’s session, if allowed to influence the array parameter input, for example via phishing. If successful, an attacker may read or modify data in the authenticated browser context, including session tokens in local storage. This issue has been patched in version 7.0.0. Affected versions
0.1.0
5.10.0
5.10.1
5.11.0
5.11.1
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
+ 40 more Show less
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.20.0
5.9.2b0
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.10.5
6.10.6
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
7.0.0rc2
7.0.0rc3
Fixed in
7.0.0
Updated May 20, 2026 · Source: OSV.dev | ||
7.1.0
minor
| ||
6.10.5
patch
3 CVEs
CVE-2026-42088
PYSEC-2026-2245
GHSA-2wvh-87g2-89hr
May 04, 2026
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. Prior to version 7.0.0-rc3, the Script Runner widget allows users to execute Python and Ruby scripts directly from the openc3-COSMOS-script-runner-api container. Because all the docker containers share a network, users can execute specially crafted scripts to bypass the API permissions check and perform administrative actions, including reading and modifying data inside the Redis database, which can be used to read secrets and change COSMOS settings, as well as read and write to the buckets service, which holds configuration, log, and plugin files. These actions are normally only available from the Admin Console or with administrative privileges. Any user with permission to create and run scripts can connect to any service in the docker network. This issue has been patched in version 7.0.0-rc3. Affected versions
0.1.0
5.10.0
5.10.1
5.11.0
5.11.1
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
+ 40 more Show less
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.20.0
5.9.2b0
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.10.5
6.10.6
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
7.0.0rc2
7.0.0rc3
Fixed in
7.0.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-42087
PYSEC-2026-2244
GHSA-v529-vhwc-wfc5
May 04, 2026
9.6
/ 10
Critical
Network
Low
Low
None
Changed
High
High
None
OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. From version 6.7.0 to before version 7.0.0-rc3, a SQL injection vulnerability exists in the Time-Series Database (TSDB) component of COSMOS. The tsdb_lookup function in the cvt_model.rb file directly places user-supplied input into a SQL query without sanitizing the input. As a result, a user can break out of the initial SQL statement and execute arbitrary SQL commands, including deleting data. This issue has been patched in version 7.0.0-rc3. Affected versions
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.10.5
6.10.6
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
+ 3 more Show less
6.9.2
7.0.0rc2
7.0.0rc3
Fixed in
7.0.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-42086
PYSEC-2026-105
GHSA-ffq5-qpvf-xq7x
May 04, 2026
4.6
/ 10
Medium
Network
Low
Low
Required
Unchanged
Low
Low
None
OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. Prior to version 7.0.0, the Command Sender UI uses an unsafe eval() function on array-like command parameters, which allows a user-supplied payload to execute in the browser when sending a command. This creates a self-XSS risk because an attacker can trigger their own script execution in the victim’s session, if allowed to influence the array parameter input, for example via phishing. If successful, an attacker may read or modify data in the authenticated browser context, including session tokens in local storage. This issue has been patched in version 7.0.0. Affected versions
0.1.0
5.10.0
5.10.1
5.11.0
5.11.1
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
+ 40 more Show less
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.20.0
5.9.2b0
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.10.5
6.10.6
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
7.0.0rc2
7.0.0rc3
Fixed in
7.0.0
Updated May 20, 2026 · Source: OSV.dev | ||
7.0.1
patch
| ||
7.0.0
major
| ||
7.0.0rc3
pre
3 CVEs
CVE-2026-42088
PYSEC-2026-2245
GHSA-2wvh-87g2-89hr
May 04, 2026
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. Prior to version 7.0.0-rc3, the Script Runner widget allows users to execute Python and Ruby scripts directly from the openc3-COSMOS-script-runner-api container. Because all the docker containers share a network, users can execute specially crafted scripts to bypass the API permissions check and perform administrative actions, including reading and modifying data inside the Redis database, which can be used to read secrets and change COSMOS settings, as well as read and write to the buckets service, which holds configuration, log, and plugin files. These actions are normally only available from the Admin Console or with administrative privileges. Any user with permission to create and run scripts can connect to any service in the docker network. This issue has been patched in version 7.0.0-rc3. Affected versions
0.1.0
5.10.0
5.10.1
5.11.0
5.11.1
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
+ 40 more Show less
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.20.0
5.9.2b0
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.10.5
6.10.6
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
7.0.0rc2
7.0.0rc3
Fixed in
7.0.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-42087
PYSEC-2026-2244
GHSA-v529-vhwc-wfc5
May 04, 2026
9.6
/ 10
Critical
Network
Low
Low
None
Changed
High
High
None
OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. From version 6.7.0 to before version 7.0.0-rc3, a SQL injection vulnerability exists in the Time-Series Database (TSDB) component of COSMOS. The tsdb_lookup function in the cvt_model.rb file directly places user-supplied input into a SQL query without sanitizing the input. As a result, a user can break out of the initial SQL statement and execute arbitrary SQL commands, including deleting data. This issue has been patched in version 7.0.0-rc3. Affected versions
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.10.5
6.10.6
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
+ 3 more Show less
6.9.2
7.0.0rc2
7.0.0rc3
Fixed in
7.0.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-42086
PYSEC-2026-105
GHSA-ffq5-qpvf-xq7x
May 04, 2026
4.6
/ 10
Medium
Network
Low
Low
Required
Unchanged
Low
Low
None
OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. Prior to version 7.0.0, the Command Sender UI uses an unsafe eval() function on array-like command parameters, which allows a user-supplied payload to execute in the browser when sending a command. This creates a self-XSS risk because an attacker can trigger their own script execution in the victim’s session, if allowed to influence the array parameter input, for example via phishing. If successful, an attacker may read or modify data in the authenticated browser context, including session tokens in local storage. This issue has been patched in version 7.0.0. Affected versions
0.1.0
5.10.0
5.10.1
5.11.0
5.11.1
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
+ 40 more Show less
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.20.0
5.9.2b0
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.10.5
6.10.6
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
7.0.0rc2
7.0.0rc3
Fixed in
7.0.0
Updated May 20, 2026 · Source: OSV.dev |
7.0.0rc3
pre
Dependencies (16)
+ 8 more
Changelog
Compare changes
|
|
7.0.0rc2
pre
3 CVEs
CVE-2026-42088
PYSEC-2026-2245
GHSA-2wvh-87g2-89hr
May 04, 2026
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. Prior to version 7.0.0-rc3, the Script Runner widget allows users to execute Python and Ruby scripts directly from the openc3-COSMOS-script-runner-api container. Because all the docker containers share a network, users can execute specially crafted scripts to bypass the API permissions check and perform administrative actions, including reading and modifying data inside the Redis database, which can be used to read secrets and change COSMOS settings, as well as read and write to the buckets service, which holds configuration, log, and plugin files. These actions are normally only available from the Admin Console or with administrative privileges. Any user with permission to create and run scripts can connect to any service in the docker network. This issue has been patched in version 7.0.0-rc3. Affected versions
0.1.0
5.10.0
5.10.1
5.11.0
5.11.1
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
+ 40 more Show less
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.20.0
5.9.2b0
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.10.5
6.10.6
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
7.0.0rc2
7.0.0rc3
Fixed in
7.0.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-42087
PYSEC-2026-2244
GHSA-v529-vhwc-wfc5
May 04, 2026
9.6
/ 10
Critical
Network
Low
Low
None
Changed
High
High
None
OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. From version 6.7.0 to before version 7.0.0-rc3, a SQL injection vulnerability exists in the Time-Series Database (TSDB) component of COSMOS. The tsdb_lookup function in the cvt_model.rb file directly places user-supplied input into a SQL query without sanitizing the input. As a result, a user can break out of the initial SQL statement and execute arbitrary SQL commands, including deleting data. This issue has been patched in version 7.0.0-rc3. Affected versions
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.10.5
6.10.6
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
+ 3 more Show less
6.9.2
7.0.0rc2
7.0.0rc3
Fixed in
7.0.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-42086
PYSEC-2026-105
GHSA-ffq5-qpvf-xq7x
May 04, 2026
4.6
/ 10
Medium
Network
Low
Low
Required
Unchanged
Low
Low
None
OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. Prior to version 7.0.0, the Command Sender UI uses an unsafe eval() function on array-like command parameters, which allows a user-supplied payload to execute in the browser when sending a command. This creates a self-XSS risk because an attacker can trigger their own script execution in the victim’s session, if allowed to influence the array parameter input, for example via phishing. If successful, an attacker may read or modify data in the authenticated browser context, including session tokens in local storage. This issue has been patched in version 7.0.0. Affected versions
0.1.0
5.10.0
5.10.1
5.11.0
5.11.1
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
+ 40 more Show less
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.20.0
5.9.2b0
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.10.5
6.10.6
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
7.0.0rc2
7.0.0rc3
Fixed in
7.0.0
Updated May 20, 2026 · Source: OSV.dev |
7.0.0rc2
pre
Dependencies (16)
+ 8 more
Changelog
Compare changes
|
|
6.10.4
patch
5 CVEs
CVE-2026-42088
PYSEC-2026-2245
GHSA-2wvh-87g2-89hr
May 04, 2026
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. Prior to version 7.0.0-rc3, the Script Runner widget allows users to execute Python and Ruby scripts directly from the openc3-COSMOS-script-runner-api container. Because all the docker containers share a network, users can execute specially crafted scripts to bypass the API permissions check and perform administrative actions, including reading and modifying data inside the Redis database, which can be used to read secrets and change COSMOS settings, as well as read and write to the buckets service, which holds configuration, log, and plugin files. These actions are normally only available from the Admin Console or with administrative privileges. Any user with permission to create and run scripts can connect to any service in the docker network. This issue has been patched in version 7.0.0-rc3. Affected versions
0.1.0
5.10.0
5.10.1
5.11.0
5.11.1
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
+ 40 more Show less
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.20.0
5.9.2b0
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.10.5
6.10.6
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
7.0.0rc2
7.0.0rc3
Fixed in
7.0.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-42087
PYSEC-2026-2244
GHSA-v529-vhwc-wfc5
May 04, 2026
9.6
/ 10
Critical
Network
Low
Low
None
Changed
High
High
None
OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. From version 6.7.0 to before version 7.0.0-rc3, a SQL injection vulnerability exists in the Time-Series Database (TSDB) component of COSMOS. The tsdb_lookup function in the cvt_model.rb file directly places user-supplied input into a SQL query without sanitizing the input. As a result, a user can break out of the initial SQL statement and execute arbitrary SQL commands, including deleting data. This issue has been patched in version 7.0.0-rc3. Affected versions
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.10.5
6.10.6
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
+ 3 more Show less
6.9.2
7.0.0rc2
7.0.0rc3
Fixed in
7.0.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-42086
PYSEC-2026-105
GHSA-ffq5-qpvf-xq7x
May 04, 2026
4.6
/ 10
Medium
Network
Low
Low
Required
Unchanged
Low
Low
None
OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. Prior to version 7.0.0, the Command Sender UI uses an unsafe eval() function on array-like command parameters, which allows a user-supplied payload to execute in the browser when sending a command. This creates a self-XSS risk because an attacker can trigger their own script execution in the victim’s session, if allowed to influence the array parameter input, for example via phishing. If successful, an attacker may read or modify data in the authenticated browser context, including session tokens in local storage. This issue has been patched in version 7.0.0. Affected versions
0.1.0
5.10.0
5.10.1
5.11.0
5.11.1
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
+ 40 more Show less
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.20.0
5.9.2b0
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.10.5
6.10.6
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
7.0.0rc2
7.0.0rc3
Fixed in
7.0.0
Updated May 20, 2026 · Source: OSV.dev
CVE-2026-42085
PYSEC-2026-2243
GHSA-4jvx-93h3-f45h
May 04, 2026
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
None
OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. Prior to versions 6.10.5 and 7.0.0-rc3, OpenC3 COSMOS contains a design flaw in the save_tool_config() function that allows saving tool configuration files at arbitrary locations inside the shared /plugins directory tree by supplying crafted configuration filenames. Although the implementation sufficiently mitigates standard path traversal attacks, by canonicalizing filename to an absolute path, all plugins share this same root directory. That enables users to create arbitrary file structures and overwrite existing configuration files within the shared /plugins directory. This issue has been patched in versions 6.10.5 and 7.0.0-rc3. Affected versions
0.1.0
5.10.0
5.10.1
5.11.0
5.11.1
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
+ 36 more Show less
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.20.0
5.9.2b0
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
Fixed in
6.10.5
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-42084
PYSEC-2026-2242
GHSA-wgx6-g857-jjf7
May 04, 2026
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. Prior to versions 6.10.5 and 7.0.0-rc3, the OpenC3 password change functionality allows a user to change their password without providing the old password, by accepting a valid session token instead. In assumed breach scenarios, this behaviour can be exploited by an attacker who has already obtained a valid session token, to gain persistence in hijacked account (including admin) and prevent legitimate users from accessing the account. This issue has been patched in versions 6.10.5 and 7.0.0-rc3. Affected versions
0.1.0
5.10.0
5.10.1
5.11.0
5.11.1
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
+ 36 more Show less
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.20.0
5.9.2b0
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
Fixed in
6.10.5
References Updated Jul 13, 2026 · Source: OSV.dev | ||
6.10.3
patch
5 CVEs
CVE-2026-42088
PYSEC-2026-2245
GHSA-2wvh-87g2-89hr
May 04, 2026
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. Prior to version 7.0.0-rc3, the Script Runner widget allows users to execute Python and Ruby scripts directly from the openc3-COSMOS-script-runner-api container. Because all the docker containers share a network, users can execute specially crafted scripts to bypass the API permissions check and perform administrative actions, including reading and modifying data inside the Redis database, which can be used to read secrets and change COSMOS settings, as well as read and write to the buckets service, which holds configuration, log, and plugin files. These actions are normally only available from the Admin Console or with administrative privileges. Any user with permission to create and run scripts can connect to any service in the docker network. This issue has been patched in version 7.0.0-rc3. Affected versions
0.1.0
5.10.0
5.10.1
5.11.0
5.11.1
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
+ 40 more Show less
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.20.0
5.9.2b0
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.10.5
6.10.6
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
7.0.0rc2
7.0.0rc3
Fixed in
7.0.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-42087
PYSEC-2026-2244
GHSA-v529-vhwc-wfc5
May 04, 2026
9.6
/ 10
Critical
Network
Low
Low
None
Changed
High
High
None
OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. From version 6.7.0 to before version 7.0.0-rc3, a SQL injection vulnerability exists in the Time-Series Database (TSDB) component of COSMOS. The tsdb_lookup function in the cvt_model.rb file directly places user-supplied input into a SQL query without sanitizing the input. As a result, a user can break out of the initial SQL statement and execute arbitrary SQL commands, including deleting data. This issue has been patched in version 7.0.0-rc3. Affected versions
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.10.5
6.10.6
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
+ 3 more Show less
6.9.2
7.0.0rc2
7.0.0rc3
Fixed in
7.0.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-42086
PYSEC-2026-105
GHSA-ffq5-qpvf-xq7x
May 04, 2026
4.6
/ 10
Medium
Network
Low
Low
Required
Unchanged
Low
Low
None
OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. Prior to version 7.0.0, the Command Sender UI uses an unsafe eval() function on array-like command parameters, which allows a user-supplied payload to execute in the browser when sending a command. This creates a self-XSS risk because an attacker can trigger their own script execution in the victim’s session, if allowed to influence the array parameter input, for example via phishing. If successful, an attacker may read or modify data in the authenticated browser context, including session tokens in local storage. This issue has been patched in version 7.0.0. Affected versions
0.1.0
5.10.0
5.10.1
5.11.0
5.11.1
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
+ 40 more Show less
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.20.0
5.9.2b0
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.10.5
6.10.6
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
7.0.0rc2
7.0.0rc3
Fixed in
7.0.0
Updated May 20, 2026 · Source: OSV.dev
CVE-2026-42085
PYSEC-2026-2243
GHSA-4jvx-93h3-f45h
May 04, 2026
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
None
OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. Prior to versions 6.10.5 and 7.0.0-rc3, OpenC3 COSMOS contains a design flaw in the save_tool_config() function that allows saving tool configuration files at arbitrary locations inside the shared /plugins directory tree by supplying crafted configuration filenames. Although the implementation sufficiently mitigates standard path traversal attacks, by canonicalizing filename to an absolute path, all plugins share this same root directory. That enables users to create arbitrary file structures and overwrite existing configuration files within the shared /plugins directory. This issue has been patched in versions 6.10.5 and 7.0.0-rc3. Affected versions
0.1.0
5.10.0
5.10.1
5.11.0
5.11.1
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
+ 36 more Show less
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.20.0
5.9.2b0
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
Fixed in
6.10.5
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-42084
PYSEC-2026-2242
GHSA-wgx6-g857-jjf7
May 04, 2026
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. Prior to versions 6.10.5 and 7.0.0-rc3, the OpenC3 password change functionality allows a user to change their password without providing the old password, by accepting a valid session token instead. In assumed breach scenarios, this behaviour can be exploited by an attacker who has already obtained a valid session token, to gain persistence in hijacked account (including admin) and prevent legitimate users from accessing the account. This issue has been patched in versions 6.10.5 and 7.0.0-rc3. Affected versions
0.1.0
5.10.0
5.10.1
5.11.0
5.11.1
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
+ 36 more Show less
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.20.0
5.9.2b0
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
Fixed in
6.10.5
References Updated Jul 13, 2026 · Source: OSV.dev | ||
6.10.2
patch
5 CVEs
CVE-2026-42088
PYSEC-2026-2245
GHSA-2wvh-87g2-89hr
May 04, 2026
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. Prior to version 7.0.0-rc3, the Script Runner widget allows users to execute Python and Ruby scripts directly from the openc3-COSMOS-script-runner-api container. Because all the docker containers share a network, users can execute specially crafted scripts to bypass the API permissions check and perform administrative actions, including reading and modifying data inside the Redis database, which can be used to read secrets and change COSMOS settings, as well as read and write to the buckets service, which holds configuration, log, and plugin files. These actions are normally only available from the Admin Console or with administrative privileges. Any user with permission to create and run scripts can connect to any service in the docker network. This issue has been patched in version 7.0.0-rc3. Affected versions
0.1.0
5.10.0
5.10.1
5.11.0
5.11.1
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
+ 40 more Show less
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.20.0
5.9.2b0
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.10.5
6.10.6
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
7.0.0rc2
7.0.0rc3
Fixed in
7.0.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-42087
PYSEC-2026-2244
GHSA-v529-vhwc-wfc5
May 04, 2026
9.6
/ 10
Critical
Network
Low
Low
None
Changed
High
High
None
OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. From version 6.7.0 to before version 7.0.0-rc3, a SQL injection vulnerability exists in the Time-Series Database (TSDB) component of COSMOS. The tsdb_lookup function in the cvt_model.rb file directly places user-supplied input into a SQL query without sanitizing the input. As a result, a user can break out of the initial SQL statement and execute arbitrary SQL commands, including deleting data. This issue has been patched in version 7.0.0-rc3. Affected versions
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.10.5
6.10.6
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
+ 3 more Show less
6.9.2
7.0.0rc2
7.0.0rc3
Fixed in
7.0.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-42086
PYSEC-2026-105
GHSA-ffq5-qpvf-xq7x
May 04, 2026
4.6
/ 10
Medium
Network
Low
Low
Required
Unchanged
Low
Low
None
OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. Prior to version 7.0.0, the Command Sender UI uses an unsafe eval() function on array-like command parameters, which allows a user-supplied payload to execute in the browser when sending a command. This creates a self-XSS risk because an attacker can trigger their own script execution in the victim’s session, if allowed to influence the array parameter input, for example via phishing. If successful, an attacker may read or modify data in the authenticated browser context, including session tokens in local storage. This issue has been patched in version 7.0.0. Affected versions
0.1.0
5.10.0
5.10.1
5.11.0
5.11.1
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
+ 40 more Show less
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.20.0
5.9.2b0
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.10.5
6.10.6
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
7.0.0rc2
7.0.0rc3
Fixed in
7.0.0
Updated May 20, 2026 · Source: OSV.dev
CVE-2026-42085
PYSEC-2026-2243
GHSA-4jvx-93h3-f45h
May 04, 2026
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
None
OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. Prior to versions 6.10.5 and 7.0.0-rc3, OpenC3 COSMOS contains a design flaw in the save_tool_config() function that allows saving tool configuration files at arbitrary locations inside the shared /plugins directory tree by supplying crafted configuration filenames. Although the implementation sufficiently mitigates standard path traversal attacks, by canonicalizing filename to an absolute path, all plugins share this same root directory. That enables users to create arbitrary file structures and overwrite existing configuration files within the shared /plugins directory. This issue has been patched in versions 6.10.5 and 7.0.0-rc3. Affected versions
0.1.0
5.10.0
5.10.1
5.11.0
5.11.1
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
+ 36 more Show less
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.20.0
5.9.2b0
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
Fixed in
6.10.5
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-42084
PYSEC-2026-2242
GHSA-wgx6-g857-jjf7
May 04, 2026
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. Prior to versions 6.10.5 and 7.0.0-rc3, the OpenC3 password change functionality allows a user to change their password without providing the old password, by accepting a valid session token instead. In assumed breach scenarios, this behaviour can be exploited by an attacker who has already obtained a valid session token, to gain persistence in hijacked account (including admin) and prevent legitimate users from accessing the account. This issue has been patched in versions 6.10.5 and 7.0.0-rc3. Affected versions
0.1.0
5.10.0
5.10.1
5.11.0
5.11.1
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
+ 36 more Show less
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.20.0
5.9.2b0
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
Fixed in
6.10.5
References Updated Jul 13, 2026 · Source: OSV.dev | ||
6.10.1
patch
5 CVEs
CVE-2026-42088
PYSEC-2026-2245
GHSA-2wvh-87g2-89hr
May 04, 2026
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. Prior to version 7.0.0-rc3, the Script Runner widget allows users to execute Python and Ruby scripts directly from the openc3-COSMOS-script-runner-api container. Because all the docker containers share a network, users can execute specially crafted scripts to bypass the API permissions check and perform administrative actions, including reading and modifying data inside the Redis database, which can be used to read secrets and change COSMOS settings, as well as read and write to the buckets service, which holds configuration, log, and plugin files. These actions are normally only available from the Admin Console or with administrative privileges. Any user with permission to create and run scripts can connect to any service in the docker network. This issue has been patched in version 7.0.0-rc3. Affected versions
0.1.0
5.10.0
5.10.1
5.11.0
5.11.1
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
+ 40 more Show less
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.20.0
5.9.2b0
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.10.5
6.10.6
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
7.0.0rc2
7.0.0rc3
Fixed in
7.0.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-42087
PYSEC-2026-2244
GHSA-v529-vhwc-wfc5
May 04, 2026
9.6
/ 10
Critical
Network
Low
Low
None
Changed
High
High
None
OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. From version 6.7.0 to before version 7.0.0-rc3, a SQL injection vulnerability exists in the Time-Series Database (TSDB) component of COSMOS. The tsdb_lookup function in the cvt_model.rb file directly places user-supplied input into a SQL query without sanitizing the input. As a result, a user can break out of the initial SQL statement and execute arbitrary SQL commands, including deleting data. This issue has been patched in version 7.0.0-rc3. Affected versions
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.10.5
6.10.6
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
+ 3 more Show less
6.9.2
7.0.0rc2
7.0.0rc3
Fixed in
7.0.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-42086
PYSEC-2026-105
GHSA-ffq5-qpvf-xq7x
May 04, 2026
4.6
/ 10
Medium
Network
Low
Low
Required
Unchanged
Low
Low
None
OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. Prior to version 7.0.0, the Command Sender UI uses an unsafe eval() function on array-like command parameters, which allows a user-supplied payload to execute in the browser when sending a command. This creates a self-XSS risk because an attacker can trigger their own script execution in the victim’s session, if allowed to influence the array parameter input, for example via phishing. If successful, an attacker may read or modify data in the authenticated browser context, including session tokens in local storage. This issue has been patched in version 7.0.0. Affected versions
0.1.0
5.10.0
5.10.1
5.11.0
5.11.1
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
+ 40 more Show less
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.20.0
5.9.2b0
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.10.5
6.10.6
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
7.0.0rc2
7.0.0rc3
Fixed in
7.0.0
Updated May 20, 2026 · Source: OSV.dev
CVE-2026-42085
PYSEC-2026-2243
GHSA-4jvx-93h3-f45h
May 04, 2026
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
None
OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. Prior to versions 6.10.5 and 7.0.0-rc3, OpenC3 COSMOS contains a design flaw in the save_tool_config() function that allows saving tool configuration files at arbitrary locations inside the shared /plugins directory tree by supplying crafted configuration filenames. Although the implementation sufficiently mitigates standard path traversal attacks, by canonicalizing filename to an absolute path, all plugins share this same root directory. That enables users to create arbitrary file structures and overwrite existing configuration files within the shared /plugins directory. This issue has been patched in versions 6.10.5 and 7.0.0-rc3. Affected versions
0.1.0
5.10.0
5.10.1
5.11.0
5.11.1
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
+ 36 more Show less
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.20.0
5.9.2b0
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
Fixed in
6.10.5
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-42084
PYSEC-2026-2242
GHSA-wgx6-g857-jjf7
May 04, 2026
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. Prior to versions 6.10.5 and 7.0.0-rc3, the OpenC3 password change functionality allows a user to change their password without providing the old password, by accepting a valid session token instead. In assumed breach scenarios, this behaviour can be exploited by an attacker who has already obtained a valid session token, to gain persistence in hijacked account (including admin) and prevent legitimate users from accessing the account. This issue has been patched in versions 6.10.5 and 7.0.0-rc3. Affected versions
0.1.0
5.10.0
5.10.1
5.11.0
5.11.1
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
+ 36 more Show less
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.20.0
5.9.2b0
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
Fixed in
6.10.5
References Updated Jul 13, 2026 · Source: OSV.dev | ||
6.10.0
minor
5 CVEs
CVE-2026-42088
PYSEC-2026-2245
GHSA-2wvh-87g2-89hr
May 04, 2026
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. Prior to version 7.0.0-rc3, the Script Runner widget allows users to execute Python and Ruby scripts directly from the openc3-COSMOS-script-runner-api container. Because all the docker containers share a network, users can execute specially crafted scripts to bypass the API permissions check and perform administrative actions, including reading and modifying data inside the Redis database, which can be used to read secrets and change COSMOS settings, as well as read and write to the buckets service, which holds configuration, log, and plugin files. These actions are normally only available from the Admin Console or with administrative privileges. Any user with permission to create and run scripts can connect to any service in the docker network. This issue has been patched in version 7.0.0-rc3. Affected versions
0.1.0
5.10.0
5.10.1
5.11.0
5.11.1
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
+ 40 more Show less
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.20.0
5.9.2b0
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.10.5
6.10.6
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
7.0.0rc2
7.0.0rc3
Fixed in
7.0.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-42087
PYSEC-2026-2244
GHSA-v529-vhwc-wfc5
May 04, 2026
9.6
/ 10
Critical
Network
Low
Low
None
Changed
High
High
None
OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. From version 6.7.0 to before version 7.0.0-rc3, a SQL injection vulnerability exists in the Time-Series Database (TSDB) component of COSMOS. The tsdb_lookup function in the cvt_model.rb file directly places user-supplied input into a SQL query without sanitizing the input. As a result, a user can break out of the initial SQL statement and execute arbitrary SQL commands, including deleting data. This issue has been patched in version 7.0.0-rc3. Affected versions
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.10.5
6.10.6
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
+ 3 more Show less
6.9.2
7.0.0rc2
7.0.0rc3
Fixed in
7.0.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-42086
PYSEC-2026-105
GHSA-ffq5-qpvf-xq7x
May 04, 2026
4.6
/ 10
Medium
Network
Low
Low
Required
Unchanged
Low
Low
None
OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. Prior to version 7.0.0, the Command Sender UI uses an unsafe eval() function on array-like command parameters, which allows a user-supplied payload to execute in the browser when sending a command. This creates a self-XSS risk because an attacker can trigger their own script execution in the victim’s session, if allowed to influence the array parameter input, for example via phishing. If successful, an attacker may read or modify data in the authenticated browser context, including session tokens in local storage. This issue has been patched in version 7.0.0. Affected versions
0.1.0
5.10.0
5.10.1
5.11.0
5.11.1
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
+ 40 more Show less
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.20.0
5.9.2b0
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.10.5
6.10.6
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
7.0.0rc2
7.0.0rc3
Fixed in
7.0.0
Updated May 20, 2026 · Source: OSV.dev
CVE-2026-42085
PYSEC-2026-2243
GHSA-4jvx-93h3-f45h
May 04, 2026
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
None
OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. Prior to versions 6.10.5 and 7.0.0-rc3, OpenC3 COSMOS contains a design flaw in the save_tool_config() function that allows saving tool configuration files at arbitrary locations inside the shared /plugins directory tree by supplying crafted configuration filenames. Although the implementation sufficiently mitigates standard path traversal attacks, by canonicalizing filename to an absolute path, all plugins share this same root directory. That enables users to create arbitrary file structures and overwrite existing configuration files within the shared /plugins directory. This issue has been patched in versions 6.10.5 and 7.0.0-rc3. Affected versions
0.1.0
5.10.0
5.10.1
5.11.0
5.11.1
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
+ 36 more Show less
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.20.0
5.9.2b0
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
Fixed in
6.10.5
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-42084
PYSEC-2026-2242
GHSA-wgx6-g857-jjf7
May 04, 2026
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. Prior to versions 6.10.5 and 7.0.0-rc3, the OpenC3 password change functionality allows a user to change their password without providing the old password, by accepting a valid session token instead. In assumed breach scenarios, this behaviour can be exploited by an attacker who has already obtained a valid session token, to gain persistence in hijacked account (including admin) and prevent legitimate users from accessing the account. This issue has been patched in versions 6.10.5 and 7.0.0-rc3. Affected versions
0.1.0
5.10.0
5.10.1
5.11.0
5.11.1
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
+ 36 more Show less
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.20.0
5.9.2b0
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
Fixed in
6.10.5
References Updated Jul 13, 2026 · Source: OSV.dev | ||
6.9.2
patch
5 CVEs
CVE-2026-42088
PYSEC-2026-2245
GHSA-2wvh-87g2-89hr
May 04, 2026
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. Prior to version 7.0.0-rc3, the Script Runner widget allows users to execute Python and Ruby scripts directly from the openc3-COSMOS-script-runner-api container. Because all the docker containers share a network, users can execute specially crafted scripts to bypass the API permissions check and perform administrative actions, including reading and modifying data inside the Redis database, which can be used to read secrets and change COSMOS settings, as well as read and write to the buckets service, which holds configuration, log, and plugin files. These actions are normally only available from the Admin Console or with administrative privileges. Any user with permission to create and run scripts can connect to any service in the docker network. This issue has been patched in version 7.0.0-rc3. Affected versions
0.1.0
5.10.0
5.10.1
5.11.0
5.11.1
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
+ 40 more Show less
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.20.0
5.9.2b0
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.10.5
6.10.6
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
7.0.0rc2
7.0.0rc3
Fixed in
7.0.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-42087
PYSEC-2026-2244
GHSA-v529-vhwc-wfc5
May 04, 2026
9.6
/ 10
Critical
Network
Low
Low
None
Changed
High
High
None
OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. From version 6.7.0 to before version 7.0.0-rc3, a SQL injection vulnerability exists in the Time-Series Database (TSDB) component of COSMOS. The tsdb_lookup function in the cvt_model.rb file directly places user-supplied input into a SQL query without sanitizing the input. As a result, a user can break out of the initial SQL statement and execute arbitrary SQL commands, including deleting data. This issue has been patched in version 7.0.0-rc3. Affected versions
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.10.5
6.10.6
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
+ 3 more Show less
6.9.2
7.0.0rc2
7.0.0rc3
Fixed in
7.0.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-42086
PYSEC-2026-105
GHSA-ffq5-qpvf-xq7x
May 04, 2026
4.6
/ 10
Medium
Network
Low
Low
Required
Unchanged
Low
Low
None
OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. Prior to version 7.0.0, the Command Sender UI uses an unsafe eval() function on array-like command parameters, which allows a user-supplied payload to execute in the browser when sending a command. This creates a self-XSS risk because an attacker can trigger their own script execution in the victim’s session, if allowed to influence the array parameter input, for example via phishing. If successful, an attacker may read or modify data in the authenticated browser context, including session tokens in local storage. This issue has been patched in version 7.0.0. Affected versions
0.1.0
5.10.0
5.10.1
5.11.0
5.11.1
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
+ 40 more Show less
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.20.0
5.9.2b0
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.10.5
6.10.6
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
7.0.0rc2
7.0.0rc3
Fixed in
7.0.0
Updated May 20, 2026 · Source: OSV.dev
CVE-2026-42085
PYSEC-2026-2243
GHSA-4jvx-93h3-f45h
May 04, 2026
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
None
OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. Prior to versions 6.10.5 and 7.0.0-rc3, OpenC3 COSMOS contains a design flaw in the save_tool_config() function that allows saving tool configuration files at arbitrary locations inside the shared /plugins directory tree by supplying crafted configuration filenames. Although the implementation sufficiently mitigates standard path traversal attacks, by canonicalizing filename to an absolute path, all plugins share this same root directory. That enables users to create arbitrary file structures and overwrite existing configuration files within the shared /plugins directory. This issue has been patched in versions 6.10.5 and 7.0.0-rc3. Affected versions
0.1.0
5.10.0
5.10.1
5.11.0
5.11.1
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
+ 36 more Show less
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.20.0
5.9.2b0
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
Fixed in
6.10.5
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-42084
PYSEC-2026-2242
GHSA-wgx6-g857-jjf7
May 04, 2026
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. Prior to versions 6.10.5 and 7.0.0-rc3, the OpenC3 password change functionality allows a user to change their password without providing the old password, by accepting a valid session token instead. In assumed breach scenarios, this behaviour can be exploited by an attacker who has already obtained a valid session token, to gain persistence in hijacked account (including admin) and prevent legitimate users from accessing the account. This issue has been patched in versions 6.10.5 and 7.0.0-rc3. Affected versions
0.1.0
5.10.0
5.10.1
5.11.0
5.11.1
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
+ 36 more Show less
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.20.0
5.9.2b0
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
Fixed in
6.10.5
References Updated Jul 13, 2026 · Source: OSV.dev | ||
6.9.1
patch
5 CVEs
CVE-2026-42088
PYSEC-2026-2245
GHSA-2wvh-87g2-89hr
May 04, 2026
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. Prior to version 7.0.0-rc3, the Script Runner widget allows users to execute Python and Ruby scripts directly from the openc3-COSMOS-script-runner-api container. Because all the docker containers share a network, users can execute specially crafted scripts to bypass the API permissions check and perform administrative actions, including reading and modifying data inside the Redis database, which can be used to read secrets and change COSMOS settings, as well as read and write to the buckets service, which holds configuration, log, and plugin files. These actions are normally only available from the Admin Console or with administrative privileges. Any user with permission to create and run scripts can connect to any service in the docker network. This issue has been patched in version 7.0.0-rc3. Affected versions
0.1.0
5.10.0
5.10.1
5.11.0
5.11.1
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
+ 40 more Show less
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.20.0
5.9.2b0
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.10.5
6.10.6
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
7.0.0rc2
7.0.0rc3
Fixed in
7.0.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-42087
PYSEC-2026-2244
GHSA-v529-vhwc-wfc5
May 04, 2026
9.6
/ 10
Critical
Network
Low
Low
None
Changed
High
High
None
OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. From version 6.7.0 to before version 7.0.0-rc3, a SQL injection vulnerability exists in the Time-Series Database (TSDB) component of COSMOS. The tsdb_lookup function in the cvt_model.rb file directly places user-supplied input into a SQL query without sanitizing the input. As a result, a user can break out of the initial SQL statement and execute arbitrary SQL commands, including deleting data. This issue has been patched in version 7.0.0-rc3. Affected versions
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.10.5
6.10.6
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
+ 3 more Show less
6.9.2
7.0.0rc2
7.0.0rc3
Fixed in
7.0.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-42086
PYSEC-2026-105
GHSA-ffq5-qpvf-xq7x
May 04, 2026
4.6
/ 10
Medium
Network
Low
Low
Required
Unchanged
Low
Low
None
OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. Prior to version 7.0.0, the Command Sender UI uses an unsafe eval() function on array-like command parameters, which allows a user-supplied payload to execute in the browser when sending a command. This creates a self-XSS risk because an attacker can trigger their own script execution in the victim’s session, if allowed to influence the array parameter input, for example via phishing. If successful, an attacker may read or modify data in the authenticated browser context, including session tokens in local storage. This issue has been patched in version 7.0.0. Affected versions
0.1.0
5.10.0
5.10.1
5.11.0
5.11.1
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
+ 40 more Show less
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.20.0
5.9.2b0
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.10.5
6.10.6
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
7.0.0rc2
7.0.0rc3
Fixed in
7.0.0
Updated May 20, 2026 · Source: OSV.dev
CVE-2026-42085
PYSEC-2026-2243
GHSA-4jvx-93h3-f45h
May 04, 2026
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
None
OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. Prior to versions 6.10.5 and 7.0.0-rc3, OpenC3 COSMOS contains a design flaw in the save_tool_config() function that allows saving tool configuration files at arbitrary locations inside the shared /plugins directory tree by supplying crafted configuration filenames. Although the implementation sufficiently mitigates standard path traversal attacks, by canonicalizing filename to an absolute path, all plugins share this same root directory. That enables users to create arbitrary file structures and overwrite existing configuration files within the shared /plugins directory. This issue has been patched in versions 6.10.5 and 7.0.0-rc3. Affected versions
0.1.0
5.10.0
5.10.1
5.11.0
5.11.1
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
+ 36 more Show less
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.20.0
5.9.2b0
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
Fixed in
6.10.5
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-42084
PYSEC-2026-2242
GHSA-wgx6-g857-jjf7
May 04, 2026
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. Prior to versions 6.10.5 and 7.0.0-rc3, the OpenC3 password change functionality allows a user to change their password without providing the old password, by accepting a valid session token instead. In assumed breach scenarios, this behaviour can be exploited by an attacker who has already obtained a valid session token, to gain persistence in hijacked account (including admin) and prevent legitimate users from accessing the account. This issue has been patched in versions 6.10.5 and 7.0.0-rc3. Affected versions
0.1.0
5.10.0
5.10.1
5.11.0
5.11.1
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
+ 36 more Show less
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.20.0
5.9.2b0
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
Fixed in
6.10.5
References Updated Jul 13, 2026 · Source: OSV.dev | ||
6.9.0
minor
5 CVEs
CVE-2026-42088
PYSEC-2026-2245
GHSA-2wvh-87g2-89hr
May 04, 2026
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. Prior to version 7.0.0-rc3, the Script Runner widget allows users to execute Python and Ruby scripts directly from the openc3-COSMOS-script-runner-api container. Because all the docker containers share a network, users can execute specially crafted scripts to bypass the API permissions check and perform administrative actions, including reading and modifying data inside the Redis database, which can be used to read secrets and change COSMOS settings, as well as read and write to the buckets service, which holds configuration, log, and plugin files. These actions are normally only available from the Admin Console or with administrative privileges. Any user with permission to create and run scripts can connect to any service in the docker network. This issue has been patched in version 7.0.0-rc3. Affected versions
0.1.0
5.10.0
5.10.1
5.11.0
5.11.1
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
+ 40 more Show less
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.20.0
5.9.2b0
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.10.5
6.10.6
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
7.0.0rc2
7.0.0rc3
Fixed in
7.0.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-42087
PYSEC-2026-2244
GHSA-v529-vhwc-wfc5
May 04, 2026
9.6
/ 10
Critical
Network
Low
Low
None
Changed
High
High
None
OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. From version 6.7.0 to before version 7.0.0-rc3, a SQL injection vulnerability exists in the Time-Series Database (TSDB) component of COSMOS. The tsdb_lookup function in the cvt_model.rb file directly places user-supplied input into a SQL query without sanitizing the input. As a result, a user can break out of the initial SQL statement and execute arbitrary SQL commands, including deleting data. This issue has been patched in version 7.0.0-rc3. Affected versions
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.10.5
6.10.6
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
+ 3 more Show less
6.9.2
7.0.0rc2
7.0.0rc3
Fixed in
7.0.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-42086
PYSEC-2026-105
GHSA-ffq5-qpvf-xq7x
May 04, 2026
4.6
/ 10
Medium
Network
Low
Low
Required
Unchanged
Low
Low
None
OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. Prior to version 7.0.0, the Command Sender UI uses an unsafe eval() function on array-like command parameters, which allows a user-supplied payload to execute in the browser when sending a command. This creates a self-XSS risk because an attacker can trigger their own script execution in the victim’s session, if allowed to influence the array parameter input, for example via phishing. If successful, an attacker may read or modify data in the authenticated browser context, including session tokens in local storage. This issue has been patched in version 7.0.0. Affected versions
0.1.0
5.10.0
5.10.1
5.11.0
5.11.1
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
+ 40 more Show less
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.20.0
5.9.2b0
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.10.5
6.10.6
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
7.0.0rc2
7.0.0rc3
Fixed in
7.0.0
Updated May 20, 2026 · Source: OSV.dev
CVE-2026-42085
PYSEC-2026-2243
GHSA-4jvx-93h3-f45h
May 04, 2026
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
None
OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. Prior to versions 6.10.5 and 7.0.0-rc3, OpenC3 COSMOS contains a design flaw in the save_tool_config() function that allows saving tool configuration files at arbitrary locations inside the shared /plugins directory tree by supplying crafted configuration filenames. Although the implementation sufficiently mitigates standard path traversal attacks, by canonicalizing filename to an absolute path, all plugins share this same root directory. That enables users to create arbitrary file structures and overwrite existing configuration files within the shared /plugins directory. This issue has been patched in versions 6.10.5 and 7.0.0-rc3. Affected versions
0.1.0
5.10.0
5.10.1
5.11.0
5.11.1
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
+ 36 more Show less
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.20.0
5.9.2b0
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
Fixed in
6.10.5
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-42084
PYSEC-2026-2242
GHSA-wgx6-g857-jjf7
May 04, 2026
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. Prior to versions 6.10.5 and 7.0.0-rc3, the OpenC3 password change functionality allows a user to change their password without providing the old password, by accepting a valid session token instead. In assumed breach scenarios, this behaviour can be exploited by an attacker who has already obtained a valid session token, to gain persistence in hijacked account (including admin) and prevent legitimate users from accessing the account. This issue has been patched in versions 6.10.5 and 7.0.0-rc3. Affected versions
0.1.0
5.10.0
5.10.1
5.11.0
5.11.1
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
+ 36 more Show less
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.20.0
5.9.2b0
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
Fixed in
6.10.5
References Updated Jul 13, 2026 · Source: OSV.dev | ||
6.8.1
patch
5 CVEs
CVE-2026-42088
PYSEC-2026-2245
GHSA-2wvh-87g2-89hr
May 04, 2026
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. Prior to version 7.0.0-rc3, the Script Runner widget allows users to execute Python and Ruby scripts directly from the openc3-COSMOS-script-runner-api container. Because all the docker containers share a network, users can execute specially crafted scripts to bypass the API permissions check and perform administrative actions, including reading and modifying data inside the Redis database, which can be used to read secrets and change COSMOS settings, as well as read and write to the buckets service, which holds configuration, log, and plugin files. These actions are normally only available from the Admin Console or with administrative privileges. Any user with permission to create and run scripts can connect to any service in the docker network. This issue has been patched in version 7.0.0-rc3. Affected versions
0.1.0
5.10.0
5.10.1
5.11.0
5.11.1
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
+ 40 more Show less
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.20.0
5.9.2b0
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.10.5
6.10.6
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
7.0.0rc2
7.0.0rc3
Fixed in
7.0.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-42087
PYSEC-2026-2244
GHSA-v529-vhwc-wfc5
May 04, 2026
9.6
/ 10
Critical
Network
Low
Low
None
Changed
High
High
None
OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. From version 6.7.0 to before version 7.0.0-rc3, a SQL injection vulnerability exists in the Time-Series Database (TSDB) component of COSMOS. The tsdb_lookup function in the cvt_model.rb file directly places user-supplied input into a SQL query without sanitizing the input. As a result, a user can break out of the initial SQL statement and execute arbitrary SQL commands, including deleting data. This issue has been patched in version 7.0.0-rc3. Affected versions
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.10.5
6.10.6
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
+ 3 more Show less
6.9.2
7.0.0rc2
7.0.0rc3
Fixed in
7.0.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-42086
PYSEC-2026-105
GHSA-ffq5-qpvf-xq7x
May 04, 2026
4.6
/ 10
Medium
Network
Low
Low
Required
Unchanged
Low
Low
None
OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. Prior to version 7.0.0, the Command Sender UI uses an unsafe eval() function on array-like command parameters, which allows a user-supplied payload to execute in the browser when sending a command. This creates a self-XSS risk because an attacker can trigger their own script execution in the victim’s session, if allowed to influence the array parameter input, for example via phishing. If successful, an attacker may read or modify data in the authenticated browser context, including session tokens in local storage. This issue has been patched in version 7.0.0. Affected versions
0.1.0
5.10.0
5.10.1
5.11.0
5.11.1
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
+ 40 more Show less
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.20.0
5.9.2b0
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.10.5
6.10.6
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
7.0.0rc2
7.0.0rc3
Fixed in
7.0.0
Updated May 20, 2026 · Source: OSV.dev
CVE-2026-42085
PYSEC-2026-2243
GHSA-4jvx-93h3-f45h
May 04, 2026
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
None
OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. Prior to versions 6.10.5 and 7.0.0-rc3, OpenC3 COSMOS contains a design flaw in the save_tool_config() function that allows saving tool configuration files at arbitrary locations inside the shared /plugins directory tree by supplying crafted configuration filenames. Although the implementation sufficiently mitigates standard path traversal attacks, by canonicalizing filename to an absolute path, all plugins share this same root directory. That enables users to create arbitrary file structures and overwrite existing configuration files within the shared /plugins directory. This issue has been patched in versions 6.10.5 and 7.0.0-rc3. Affected versions
0.1.0
5.10.0
5.10.1
5.11.0
5.11.1
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
+ 36 more Show less
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.20.0
5.9.2b0
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
Fixed in
6.10.5
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-42084
PYSEC-2026-2242
GHSA-wgx6-g857-jjf7
May 04, 2026
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. Prior to versions 6.10.5 and 7.0.0-rc3, the OpenC3 password change functionality allows a user to change their password without providing the old password, by accepting a valid session token instead. In assumed breach scenarios, this behaviour can be exploited by an attacker who has already obtained a valid session token, to gain persistence in hijacked account (including admin) and prevent legitimate users from accessing the account. This issue has been patched in versions 6.10.5 and 7.0.0-rc3. Affected versions
0.1.0
5.10.0
5.10.1
5.11.0
5.11.1
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
+ 36 more Show less
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.20.0
5.9.2b0
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
Fixed in
6.10.5
References Updated Jul 13, 2026 · Source: OSV.dev | ||
6.8.0
minor
5 CVEs
CVE-2026-42088
PYSEC-2026-2245
GHSA-2wvh-87g2-89hr
May 04, 2026
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. Prior to version 7.0.0-rc3, the Script Runner widget allows users to execute Python and Ruby scripts directly from the openc3-COSMOS-script-runner-api container. Because all the docker containers share a network, users can execute specially crafted scripts to bypass the API permissions check and perform administrative actions, including reading and modifying data inside the Redis database, which can be used to read secrets and change COSMOS settings, as well as read and write to the buckets service, which holds configuration, log, and plugin files. These actions are normally only available from the Admin Console or with administrative privileges. Any user with permission to create and run scripts can connect to any service in the docker network. This issue has been patched in version 7.0.0-rc3. Affected versions
0.1.0
5.10.0
5.10.1
5.11.0
5.11.1
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
+ 40 more Show less
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.20.0
5.9.2b0
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.10.5
6.10.6
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
7.0.0rc2
7.0.0rc3
Fixed in
7.0.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-42087
PYSEC-2026-2244
GHSA-v529-vhwc-wfc5
May 04, 2026
9.6
/ 10
Critical
Network
Low
Low
None
Changed
High
High
None
OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. From version 6.7.0 to before version 7.0.0-rc3, a SQL injection vulnerability exists in the Time-Series Database (TSDB) component of COSMOS. The tsdb_lookup function in the cvt_model.rb file directly places user-supplied input into a SQL query without sanitizing the input. As a result, a user can break out of the initial SQL statement and execute arbitrary SQL commands, including deleting data. This issue has been patched in version 7.0.0-rc3. Affected versions
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.10.5
6.10.6
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
+ 3 more Show less
6.9.2
7.0.0rc2
7.0.0rc3
Fixed in
7.0.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-42086
PYSEC-2026-105
GHSA-ffq5-qpvf-xq7x
May 04, 2026
4.6
/ 10
Medium
Network
Low
Low
Required
Unchanged
Low
Low
None
OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. Prior to version 7.0.0, the Command Sender UI uses an unsafe eval() function on array-like command parameters, which allows a user-supplied payload to execute in the browser when sending a command. This creates a self-XSS risk because an attacker can trigger their own script execution in the victim’s session, if allowed to influence the array parameter input, for example via phishing. If successful, an attacker may read or modify data in the authenticated browser context, including session tokens in local storage. This issue has been patched in version 7.0.0. Affected versions
0.1.0
5.10.0
5.10.1
5.11.0
5.11.1
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
+ 40 more Show less
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.20.0
5.9.2b0
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.10.5
6.10.6
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
7.0.0rc2
7.0.0rc3
Fixed in
7.0.0
Updated May 20, 2026 · Source: OSV.dev
CVE-2026-42085
PYSEC-2026-2243
GHSA-4jvx-93h3-f45h
May 04, 2026
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
None
OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. Prior to versions 6.10.5 and 7.0.0-rc3, OpenC3 COSMOS contains a design flaw in the save_tool_config() function that allows saving tool configuration files at arbitrary locations inside the shared /plugins directory tree by supplying crafted configuration filenames. Although the implementation sufficiently mitigates standard path traversal attacks, by canonicalizing filename to an absolute path, all plugins share this same root directory. That enables users to create arbitrary file structures and overwrite existing configuration files within the shared /plugins directory. This issue has been patched in versions 6.10.5 and 7.0.0-rc3. Affected versions
0.1.0
5.10.0
5.10.1
5.11.0
5.11.1
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
+ 36 more Show less
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.20.0
5.9.2b0
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
Fixed in
6.10.5
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-42084
PYSEC-2026-2242
GHSA-wgx6-g857-jjf7
May 04, 2026
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. Prior to versions 6.10.5 and 7.0.0-rc3, the OpenC3 password change functionality allows a user to change their password without providing the old password, by accepting a valid session token instead. In assumed breach scenarios, this behaviour can be exploited by an attacker who has already obtained a valid session token, to gain persistence in hijacked account (including admin) and prevent legitimate users from accessing the account. This issue has been patched in versions 6.10.5 and 7.0.0-rc3. Affected versions
0.1.0
5.10.0
5.10.1
5.11.0
5.11.1
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
+ 36 more Show less
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.20.0
5.9.2b0
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
Fixed in
6.10.5
References Updated Jul 13, 2026 · Source: OSV.dev | ||
6.7.0
minor
5 CVEs
CVE-2026-42088
PYSEC-2026-2245
GHSA-2wvh-87g2-89hr
May 04, 2026
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. Prior to version 7.0.0-rc3, the Script Runner widget allows users to execute Python and Ruby scripts directly from the openc3-COSMOS-script-runner-api container. Because all the docker containers share a network, users can execute specially crafted scripts to bypass the API permissions check and perform administrative actions, including reading and modifying data inside the Redis database, which can be used to read secrets and change COSMOS settings, as well as read and write to the buckets service, which holds configuration, log, and plugin files. These actions are normally only available from the Admin Console or with administrative privileges. Any user with permission to create and run scripts can connect to any service in the docker network. This issue has been patched in version 7.0.0-rc3. Affected versions
0.1.0
5.10.0
5.10.1
5.11.0
5.11.1
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
+ 40 more Show less
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.20.0
5.9.2b0
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.10.5
6.10.6
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
7.0.0rc2
7.0.0rc3
Fixed in
7.0.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-42087
PYSEC-2026-2244
GHSA-v529-vhwc-wfc5
May 04, 2026
9.6
/ 10
Critical
Network
Low
Low
None
Changed
High
High
None
OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. From version 6.7.0 to before version 7.0.0-rc3, a SQL injection vulnerability exists in the Time-Series Database (TSDB) component of COSMOS. The tsdb_lookup function in the cvt_model.rb file directly places user-supplied input into a SQL query without sanitizing the input. As a result, a user can break out of the initial SQL statement and execute arbitrary SQL commands, including deleting data. This issue has been patched in version 7.0.0-rc3. Affected versions
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.10.5
6.10.6
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
+ 3 more Show less
6.9.2
7.0.0rc2
7.0.0rc3
Fixed in
7.0.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-42086
PYSEC-2026-105
GHSA-ffq5-qpvf-xq7x
May 04, 2026
4.6
/ 10
Medium
Network
Low
Low
Required
Unchanged
Low
Low
None
OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. Prior to version 7.0.0, the Command Sender UI uses an unsafe eval() function on array-like command parameters, which allows a user-supplied payload to execute in the browser when sending a command. This creates a self-XSS risk because an attacker can trigger their own script execution in the victim’s session, if allowed to influence the array parameter input, for example via phishing. If successful, an attacker may read or modify data in the authenticated browser context, including session tokens in local storage. This issue has been patched in version 7.0.0. Affected versions
0.1.0
5.10.0
5.10.1
5.11.0
5.11.1
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
+ 40 more Show less
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.20.0
5.9.2b0
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.10.5
6.10.6
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
7.0.0rc2
7.0.0rc3
Fixed in
7.0.0
Updated May 20, 2026 · Source: OSV.dev
CVE-2026-42085
PYSEC-2026-2243
GHSA-4jvx-93h3-f45h
May 04, 2026
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
None
OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. Prior to versions 6.10.5 and 7.0.0-rc3, OpenC3 COSMOS contains a design flaw in the save_tool_config() function that allows saving tool configuration files at arbitrary locations inside the shared /plugins directory tree by supplying crafted configuration filenames. Although the implementation sufficiently mitigates standard path traversal attacks, by canonicalizing filename to an absolute path, all plugins share this same root directory. That enables users to create arbitrary file structures and overwrite existing configuration files within the shared /plugins directory. This issue has been patched in versions 6.10.5 and 7.0.0-rc3. Affected versions
0.1.0
5.10.0
5.10.1
5.11.0
5.11.1
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
+ 36 more Show less
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.20.0
5.9.2b0
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
Fixed in
6.10.5
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-42084
PYSEC-2026-2242
GHSA-wgx6-g857-jjf7
May 04, 2026
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. Prior to versions 6.10.5 and 7.0.0-rc3, the OpenC3 password change functionality allows a user to change their password without providing the old password, by accepting a valid session token instead. In assumed breach scenarios, this behaviour can be exploited by an attacker who has already obtained a valid session token, to gain persistence in hijacked account (including admin) and prevent legitimate users from accessing the account. This issue has been patched in versions 6.10.5 and 7.0.0-rc3. Affected versions
0.1.0
5.10.0
5.10.1
5.11.0
5.11.1
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
+ 36 more Show less
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.20.0
5.9.2b0
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
Fixed in
6.10.5
References Updated Jul 13, 2026 · Source: OSV.dev | ||
6.6.0
minor
4 CVEs
CVE-2026-42088
PYSEC-2026-2245
GHSA-2wvh-87g2-89hr
May 04, 2026
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. Prior to version 7.0.0-rc3, the Script Runner widget allows users to execute Python and Ruby scripts directly from the openc3-COSMOS-script-runner-api container. Because all the docker containers share a network, users can execute specially crafted scripts to bypass the API permissions check and perform administrative actions, including reading and modifying data inside the Redis database, which can be used to read secrets and change COSMOS settings, as well as read and write to the buckets service, which holds configuration, log, and plugin files. These actions are normally only available from the Admin Console or with administrative privileges. Any user with permission to create and run scripts can connect to any service in the docker network. This issue has been patched in version 7.0.0-rc3. Affected versions
0.1.0
5.10.0
5.10.1
5.11.0
5.11.1
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
+ 40 more Show less
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.20.0
5.9.2b0
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.10.5
6.10.6
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
7.0.0rc2
7.0.0rc3
Fixed in
7.0.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-42086
PYSEC-2026-105
GHSA-ffq5-qpvf-xq7x
May 04, 2026
4.6
/ 10
Medium
Network
Low
Low
Required
Unchanged
Low
Low
None
OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. Prior to version 7.0.0, the Command Sender UI uses an unsafe eval() function on array-like command parameters, which allows a user-supplied payload to execute in the browser when sending a command. This creates a self-XSS risk because an attacker can trigger their own script execution in the victim’s session, if allowed to influence the array parameter input, for example via phishing. If successful, an attacker may read or modify data in the authenticated browser context, including session tokens in local storage. This issue has been patched in version 7.0.0. Affected versions
0.1.0
5.10.0
5.10.1
5.11.0
5.11.1
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
+ 40 more Show less
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.20.0
5.9.2b0
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.10.5
6.10.6
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
7.0.0rc2
7.0.0rc3
Fixed in
7.0.0
Updated May 20, 2026 · Source: OSV.dev
CVE-2026-42085
PYSEC-2026-2243
GHSA-4jvx-93h3-f45h
May 04, 2026
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
None
OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. Prior to versions 6.10.5 and 7.0.0-rc3, OpenC3 COSMOS contains a design flaw in the save_tool_config() function that allows saving tool configuration files at arbitrary locations inside the shared /plugins directory tree by supplying crafted configuration filenames. Although the implementation sufficiently mitigates standard path traversal attacks, by canonicalizing filename to an absolute path, all plugins share this same root directory. That enables users to create arbitrary file structures and overwrite existing configuration files within the shared /plugins directory. This issue has been patched in versions 6.10.5 and 7.0.0-rc3. Affected versions
0.1.0
5.10.0
5.10.1
5.11.0
5.11.1
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
+ 36 more Show less
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.20.0
5.9.2b0
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
Fixed in
6.10.5
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-42084
PYSEC-2026-2242
GHSA-wgx6-g857-jjf7
May 04, 2026
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. Prior to versions 6.10.5 and 7.0.0-rc3, the OpenC3 password change functionality allows a user to change their password without providing the old password, by accepting a valid session token instead. In assumed breach scenarios, this behaviour can be exploited by an attacker who has already obtained a valid session token, to gain persistence in hijacked account (including admin) and prevent legitimate users from accessing the account. This issue has been patched in versions 6.10.5 and 7.0.0-rc3. Affected versions
0.1.0
5.10.0
5.10.1
5.11.0
5.11.1
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
+ 36 more Show less
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.20.0
5.9.2b0
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
Fixed in
6.10.5
References Updated Jul 13, 2026 · Source: OSV.dev | ||
6.5.1
patch
4 CVEs
CVE-2026-42088
PYSEC-2026-2245
GHSA-2wvh-87g2-89hr
May 04, 2026
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. Prior to version 7.0.0-rc3, the Script Runner widget allows users to execute Python and Ruby scripts directly from the openc3-COSMOS-script-runner-api container. Because all the docker containers share a network, users can execute specially crafted scripts to bypass the API permissions check and perform administrative actions, including reading and modifying data inside the Redis database, which can be used to read secrets and change COSMOS settings, as well as read and write to the buckets service, which holds configuration, log, and plugin files. These actions are normally only available from the Admin Console or with administrative privileges. Any user with permission to create and run scripts can connect to any service in the docker network. This issue has been patched in version 7.0.0-rc3. Affected versions
0.1.0
5.10.0
5.10.1
5.11.0
5.11.1
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
+ 40 more Show less
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.20.0
5.9.2b0
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.10.5
6.10.6
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
7.0.0rc2
7.0.0rc3
Fixed in
7.0.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-42086
PYSEC-2026-105
GHSA-ffq5-qpvf-xq7x
May 04, 2026
4.6
/ 10
Medium
Network
Low
Low
Required
Unchanged
Low
Low
None
OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. Prior to version 7.0.0, the Command Sender UI uses an unsafe eval() function on array-like command parameters, which allows a user-supplied payload to execute in the browser when sending a command. This creates a self-XSS risk because an attacker can trigger their own script execution in the victim’s session, if allowed to influence the array parameter input, for example via phishing. If successful, an attacker may read or modify data in the authenticated browser context, including session tokens in local storage. This issue has been patched in version 7.0.0. Affected versions
0.1.0
5.10.0
5.10.1
5.11.0
5.11.1
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
+ 40 more Show less
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.20.0
5.9.2b0
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.10.5
6.10.6
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
7.0.0rc2
7.0.0rc3
Fixed in
7.0.0
Updated May 20, 2026 · Source: OSV.dev
CVE-2026-42085
PYSEC-2026-2243
GHSA-4jvx-93h3-f45h
May 04, 2026
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
None
OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. Prior to versions 6.10.5 and 7.0.0-rc3, OpenC3 COSMOS contains a design flaw in the save_tool_config() function that allows saving tool configuration files at arbitrary locations inside the shared /plugins directory tree by supplying crafted configuration filenames. Although the implementation sufficiently mitigates standard path traversal attacks, by canonicalizing filename to an absolute path, all plugins share this same root directory. That enables users to create arbitrary file structures and overwrite existing configuration files within the shared /plugins directory. This issue has been patched in versions 6.10.5 and 7.0.0-rc3. Affected versions
0.1.0
5.10.0
5.10.1
5.11.0
5.11.1
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
+ 36 more Show less
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.20.0
5.9.2b0
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
Fixed in
6.10.5
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-42084
PYSEC-2026-2242
GHSA-wgx6-g857-jjf7
May 04, 2026
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. Prior to versions 6.10.5 and 7.0.0-rc3, the OpenC3 password change functionality allows a user to change their password without providing the old password, by accepting a valid session token instead. In assumed breach scenarios, this behaviour can be exploited by an attacker who has already obtained a valid session token, to gain persistence in hijacked account (including admin) and prevent legitimate users from accessing the account. This issue has been patched in versions 6.10.5 and 7.0.0-rc3. Affected versions
0.1.0
5.10.0
5.10.1
5.11.0
5.11.1
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
+ 36 more Show less
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.20.0
5.9.2b0
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
Fixed in
6.10.5
References Updated Jul 13, 2026 · Source: OSV.dev | ||
6.5.0
minor
4 CVEs
CVE-2026-42088
PYSEC-2026-2245
GHSA-2wvh-87g2-89hr
May 04, 2026
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. Prior to version 7.0.0-rc3, the Script Runner widget allows users to execute Python and Ruby scripts directly from the openc3-COSMOS-script-runner-api container. Because all the docker containers share a network, users can execute specially crafted scripts to bypass the API permissions check and perform administrative actions, including reading and modifying data inside the Redis database, which can be used to read secrets and change COSMOS settings, as well as read and write to the buckets service, which holds configuration, log, and plugin files. These actions are normally only available from the Admin Console or with administrative privileges. Any user with permission to create and run scripts can connect to any service in the docker network. This issue has been patched in version 7.0.0-rc3. Affected versions
0.1.0
5.10.0
5.10.1
5.11.0
5.11.1
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
+ 40 more Show less
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.20.0
5.9.2b0
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.10.5
6.10.6
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
7.0.0rc2
7.0.0rc3
Fixed in
7.0.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-42086
PYSEC-2026-105
GHSA-ffq5-qpvf-xq7x
May 04, 2026
4.6
/ 10
Medium
Network
Low
Low
Required
Unchanged
Low
Low
None
OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. Prior to version 7.0.0, the Command Sender UI uses an unsafe eval() function on array-like command parameters, which allows a user-supplied payload to execute in the browser when sending a command. This creates a self-XSS risk because an attacker can trigger their own script execution in the victim’s session, if allowed to influence the array parameter input, for example via phishing. If successful, an attacker may read or modify data in the authenticated browser context, including session tokens in local storage. This issue has been patched in version 7.0.0. Affected versions
0.1.0
5.10.0
5.10.1
5.11.0
5.11.1
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
+ 40 more Show less
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.20.0
5.9.2b0
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.10.5
6.10.6
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
7.0.0rc2
7.0.0rc3
Fixed in
7.0.0
Updated May 20, 2026 · Source: OSV.dev
CVE-2026-42085
PYSEC-2026-2243
GHSA-4jvx-93h3-f45h
May 04, 2026
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
None
OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. Prior to versions 6.10.5 and 7.0.0-rc3, OpenC3 COSMOS contains a design flaw in the save_tool_config() function that allows saving tool configuration files at arbitrary locations inside the shared /plugins directory tree by supplying crafted configuration filenames. Although the implementation sufficiently mitigates standard path traversal attacks, by canonicalizing filename to an absolute path, all plugins share this same root directory. That enables users to create arbitrary file structures and overwrite existing configuration files within the shared /plugins directory. This issue has been patched in versions 6.10.5 and 7.0.0-rc3. Affected versions
0.1.0
5.10.0
5.10.1
5.11.0
5.11.1
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
+ 36 more Show less
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.20.0
5.9.2b0
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
Fixed in
6.10.5
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-42084
PYSEC-2026-2242
GHSA-wgx6-g857-jjf7
May 04, 2026
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. Prior to versions 6.10.5 and 7.0.0-rc3, the OpenC3 password change functionality allows a user to change their password without providing the old password, by accepting a valid session token instead. In assumed breach scenarios, this behaviour can be exploited by an attacker who has already obtained a valid session token, to gain persistence in hijacked account (including admin) and prevent legitimate users from accessing the account. This issue has been patched in versions 6.10.5 and 7.0.0-rc3. Affected versions
0.1.0
5.10.0
5.10.1
5.11.0
5.11.1
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
+ 36 more Show less
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.20.0
5.9.2b0
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
Fixed in
6.10.5
References Updated Jul 13, 2026 · Source: OSV.dev | ||
6.4.2
patch
4 CVEs
CVE-2026-42088
PYSEC-2026-2245
GHSA-2wvh-87g2-89hr
May 04, 2026
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. Prior to version 7.0.0-rc3, the Script Runner widget allows users to execute Python and Ruby scripts directly from the openc3-COSMOS-script-runner-api container. Because all the docker containers share a network, users can execute specially crafted scripts to bypass the API permissions check and perform administrative actions, including reading and modifying data inside the Redis database, which can be used to read secrets and change COSMOS settings, as well as read and write to the buckets service, which holds configuration, log, and plugin files. These actions are normally only available from the Admin Console or with administrative privileges. Any user with permission to create and run scripts can connect to any service in the docker network. This issue has been patched in version 7.0.0-rc3. Affected versions
0.1.0
5.10.0
5.10.1
5.11.0
5.11.1
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
+ 40 more Show less
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.20.0
5.9.2b0
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.10.5
6.10.6
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
7.0.0rc2
7.0.0rc3
Fixed in
7.0.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-42086
PYSEC-2026-105
GHSA-ffq5-qpvf-xq7x
May 04, 2026
4.6
/ 10
Medium
Network
Low
Low
Required
Unchanged
Low
Low
None
OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. Prior to version 7.0.0, the Command Sender UI uses an unsafe eval() function on array-like command parameters, which allows a user-supplied payload to execute in the browser when sending a command. This creates a self-XSS risk because an attacker can trigger their own script execution in the victim’s session, if allowed to influence the array parameter input, for example via phishing. If successful, an attacker may read or modify data in the authenticated browser context, including session tokens in local storage. This issue has been patched in version 7.0.0. Affected versions
0.1.0
5.10.0
5.10.1
5.11.0
5.11.1
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
+ 40 more Show less
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.20.0
5.9.2b0
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.10.5
6.10.6
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
7.0.0rc2
7.0.0rc3
Fixed in
7.0.0
Updated May 20, 2026 · Source: OSV.dev
CVE-2026-42085
PYSEC-2026-2243
GHSA-4jvx-93h3-f45h
May 04, 2026
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
None
OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. Prior to versions 6.10.5 and 7.0.0-rc3, OpenC3 COSMOS contains a design flaw in the save_tool_config() function that allows saving tool configuration files at arbitrary locations inside the shared /plugins directory tree by supplying crafted configuration filenames. Although the implementation sufficiently mitigates standard path traversal attacks, by canonicalizing filename to an absolute path, all plugins share this same root directory. That enables users to create arbitrary file structures and overwrite existing configuration files within the shared /plugins directory. This issue has been patched in versions 6.10.5 and 7.0.0-rc3. Affected versions
0.1.0
5.10.0
5.10.1
5.11.0
5.11.1
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
+ 36 more Show less
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.20.0
5.9.2b0
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
Fixed in
6.10.5
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-42084
PYSEC-2026-2242
GHSA-wgx6-g857-jjf7
May 04, 2026
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. Prior to versions 6.10.5 and 7.0.0-rc3, the OpenC3 password change functionality allows a user to change their password without providing the old password, by accepting a valid session token instead. In assumed breach scenarios, this behaviour can be exploited by an attacker who has already obtained a valid session token, to gain persistence in hijacked account (including admin) and prevent legitimate users from accessing the account. This issue has been patched in versions 6.10.5 and 7.0.0-rc3. Affected versions
0.1.0
5.10.0
5.10.1
5.11.0
5.11.1
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
+ 36 more Show less
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.20.0
5.9.2b0
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
Fixed in
6.10.5
References Updated Jul 13, 2026 · Source: OSV.dev | ||
6.4.1
patch
4 CVEs
CVE-2026-42088
PYSEC-2026-2245
GHSA-2wvh-87g2-89hr
May 04, 2026
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. Prior to version 7.0.0-rc3, the Script Runner widget allows users to execute Python and Ruby scripts directly from the openc3-COSMOS-script-runner-api container. Because all the docker containers share a network, users can execute specially crafted scripts to bypass the API permissions check and perform administrative actions, including reading and modifying data inside the Redis database, which can be used to read secrets and change COSMOS settings, as well as read and write to the buckets service, which holds configuration, log, and plugin files. These actions are normally only available from the Admin Console or with administrative privileges. Any user with permission to create and run scripts can connect to any service in the docker network. This issue has been patched in version 7.0.0-rc3. Affected versions
0.1.0
5.10.0
5.10.1
5.11.0
5.11.1
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
+ 40 more Show less
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.20.0
5.9.2b0
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.10.5
6.10.6
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
7.0.0rc2
7.0.0rc3
Fixed in
7.0.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-42086
PYSEC-2026-105
GHSA-ffq5-qpvf-xq7x
May 04, 2026
4.6
/ 10
Medium
Network
Low
Low
Required
Unchanged
Low
Low
None
OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. Prior to version 7.0.0, the Command Sender UI uses an unsafe eval() function on array-like command parameters, which allows a user-supplied payload to execute in the browser when sending a command. This creates a self-XSS risk because an attacker can trigger their own script execution in the victim’s session, if allowed to influence the array parameter input, for example via phishing. If successful, an attacker may read or modify data in the authenticated browser context, including session tokens in local storage. This issue has been patched in version 7.0.0. Affected versions
0.1.0
5.10.0
5.10.1
5.11.0
5.11.1
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
+ 40 more Show less
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.20.0
5.9.2b0
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.10.5
6.10.6
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
7.0.0rc2
7.0.0rc3
Fixed in
7.0.0
Updated May 20, 2026 · Source: OSV.dev
CVE-2026-42085
PYSEC-2026-2243
GHSA-4jvx-93h3-f45h
May 04, 2026
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
None
OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. Prior to versions 6.10.5 and 7.0.0-rc3, OpenC3 COSMOS contains a design flaw in the save_tool_config() function that allows saving tool configuration files at arbitrary locations inside the shared /plugins directory tree by supplying crafted configuration filenames. Although the implementation sufficiently mitigates standard path traversal attacks, by canonicalizing filename to an absolute path, all plugins share this same root directory. That enables users to create arbitrary file structures and overwrite existing configuration files within the shared /plugins directory. This issue has been patched in versions 6.10.5 and 7.0.0-rc3. Affected versions
0.1.0
5.10.0
5.10.1
5.11.0
5.11.1
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
+ 36 more Show less
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.20.0
5.9.2b0
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
Fixed in
6.10.5
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-42084
PYSEC-2026-2242
GHSA-wgx6-g857-jjf7
May 04, 2026
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. Prior to versions 6.10.5 and 7.0.0-rc3, the OpenC3 password change functionality allows a user to change their password without providing the old password, by accepting a valid session token instead. In assumed breach scenarios, this behaviour can be exploited by an attacker who has already obtained a valid session token, to gain persistence in hijacked account (including admin) and prevent legitimate users from accessing the account. This issue has been patched in versions 6.10.5 and 7.0.0-rc3. Affected versions
0.1.0
5.10.0
5.10.1
5.11.0
5.11.1
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
+ 36 more Show less
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.20.0
5.9.2b0
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
Fixed in
6.10.5
References Updated Jul 13, 2026 · Source: OSV.dev | ||
6.4.0
minor
4 CVEs
CVE-2026-42088
PYSEC-2026-2245
GHSA-2wvh-87g2-89hr
May 04, 2026
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. Prior to version 7.0.0-rc3, the Script Runner widget allows users to execute Python and Ruby scripts directly from the openc3-COSMOS-script-runner-api container. Because all the docker containers share a network, users can execute specially crafted scripts to bypass the API permissions check and perform administrative actions, including reading and modifying data inside the Redis database, which can be used to read secrets and change COSMOS settings, as well as read and write to the buckets service, which holds configuration, log, and plugin files. These actions are normally only available from the Admin Console or with administrative privileges. Any user with permission to create and run scripts can connect to any service in the docker network. This issue has been patched in version 7.0.0-rc3. Affected versions
0.1.0
5.10.0
5.10.1
5.11.0
5.11.1
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
+ 40 more Show less
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.20.0
5.9.2b0
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.10.5
6.10.6
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
7.0.0rc2
7.0.0rc3
Fixed in
7.0.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-42086
PYSEC-2026-105
GHSA-ffq5-qpvf-xq7x
May 04, 2026
4.6
/ 10
Medium
Network
Low
Low
Required
Unchanged
Low
Low
None
OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. Prior to version 7.0.0, the Command Sender UI uses an unsafe eval() function on array-like command parameters, which allows a user-supplied payload to execute in the browser when sending a command. This creates a self-XSS risk because an attacker can trigger their own script execution in the victim’s session, if allowed to influence the array parameter input, for example via phishing. If successful, an attacker may read or modify data in the authenticated browser context, including session tokens in local storage. This issue has been patched in version 7.0.0. Affected versions
0.1.0
5.10.0
5.10.1
5.11.0
5.11.1
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
+ 40 more Show less
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.20.0
5.9.2b0
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.10.5
6.10.6
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
7.0.0rc2
7.0.0rc3
Fixed in
7.0.0
Updated May 20, 2026 · Source: OSV.dev
CVE-2026-42085
PYSEC-2026-2243
GHSA-4jvx-93h3-f45h
May 04, 2026
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
None
OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. Prior to versions 6.10.5 and 7.0.0-rc3, OpenC3 COSMOS contains a design flaw in the save_tool_config() function that allows saving tool configuration files at arbitrary locations inside the shared /plugins directory tree by supplying crafted configuration filenames. Although the implementation sufficiently mitigates standard path traversal attacks, by canonicalizing filename to an absolute path, all plugins share this same root directory. That enables users to create arbitrary file structures and overwrite existing configuration files within the shared /plugins directory. This issue has been patched in versions 6.10.5 and 7.0.0-rc3. Affected versions
0.1.0
5.10.0
5.10.1
5.11.0
5.11.1
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
+ 36 more Show less
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.20.0
5.9.2b0
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
Fixed in
6.10.5
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-42084
PYSEC-2026-2242
GHSA-wgx6-g857-jjf7
May 04, 2026
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. Prior to versions 6.10.5 and 7.0.0-rc3, the OpenC3 password change functionality allows a user to change their password without providing the old password, by accepting a valid session token instead. In assumed breach scenarios, this behaviour can be exploited by an attacker who has already obtained a valid session token, to gain persistence in hijacked account (including admin) and prevent legitimate users from accessing the account. This issue has been patched in versions 6.10.5 and 7.0.0-rc3. Affected versions
0.1.0
5.10.0
5.10.1
5.11.0
5.11.1
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
+ 36 more Show less
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.20.0
5.9.2b0
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
Fixed in
6.10.5
References Updated Jul 13, 2026 · Source: OSV.dev | ||
6.3.0
minor
4 CVEs
CVE-2026-42088
PYSEC-2026-2245
GHSA-2wvh-87g2-89hr
May 04, 2026
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. Prior to version 7.0.0-rc3, the Script Runner widget allows users to execute Python and Ruby scripts directly from the openc3-COSMOS-script-runner-api container. Because all the docker containers share a network, users can execute specially crafted scripts to bypass the API permissions check and perform administrative actions, including reading and modifying data inside the Redis database, which can be used to read secrets and change COSMOS settings, as well as read and write to the buckets service, which holds configuration, log, and plugin files. These actions are normally only available from the Admin Console or with administrative privileges. Any user with permission to create and run scripts can connect to any service in the docker network. This issue has been patched in version 7.0.0-rc3. Affected versions
0.1.0
5.10.0
5.10.1
5.11.0
5.11.1
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
+ 40 more Show less
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.20.0
5.9.2b0
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.10.5
6.10.6
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
7.0.0rc2
7.0.0rc3
Fixed in
7.0.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-42086
PYSEC-2026-105
GHSA-ffq5-qpvf-xq7x
May 04, 2026
4.6
/ 10
Medium
Network
Low
Low
Required
Unchanged
Low
Low
None
OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. Prior to version 7.0.0, the Command Sender UI uses an unsafe eval() function on array-like command parameters, which allows a user-supplied payload to execute in the browser when sending a command. This creates a self-XSS risk because an attacker can trigger their own script execution in the victim’s session, if allowed to influence the array parameter input, for example via phishing. If successful, an attacker may read or modify data in the authenticated browser context, including session tokens in local storage. This issue has been patched in version 7.0.0. Affected versions
0.1.0
5.10.0
5.10.1
5.11.0
5.11.1
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
+ 40 more Show less
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.20.0
5.9.2b0
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.10.5
6.10.6
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
7.0.0rc2
7.0.0rc3
Fixed in
7.0.0
Updated May 20, 2026 · Source: OSV.dev
CVE-2026-42085
PYSEC-2026-2243
GHSA-4jvx-93h3-f45h
May 04, 2026
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
None
OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. Prior to versions 6.10.5 and 7.0.0-rc3, OpenC3 COSMOS contains a design flaw in the save_tool_config() function that allows saving tool configuration files at arbitrary locations inside the shared /plugins directory tree by supplying crafted configuration filenames. Although the implementation sufficiently mitigates standard path traversal attacks, by canonicalizing filename to an absolute path, all plugins share this same root directory. That enables users to create arbitrary file structures and overwrite existing configuration files within the shared /plugins directory. This issue has been patched in versions 6.10.5 and 7.0.0-rc3. Affected versions
0.1.0
5.10.0
5.10.1
5.11.0
5.11.1
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
+ 36 more Show less
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.20.0
5.9.2b0
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
Fixed in
6.10.5
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-42084
PYSEC-2026-2242
GHSA-wgx6-g857-jjf7
May 04, 2026
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. Prior to versions 6.10.5 and 7.0.0-rc3, the OpenC3 password change functionality allows a user to change their password without providing the old password, by accepting a valid session token instead. In assumed breach scenarios, this behaviour can be exploited by an attacker who has already obtained a valid session token, to gain persistence in hijacked account (including admin) and prevent legitimate users from accessing the account. This issue has been patched in versions 6.10.5 and 7.0.0-rc3. Affected versions
0.1.0
5.10.0
5.10.1
5.11.0
5.11.1
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
+ 36 more Show less
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.20.0
5.9.2b0
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
Fixed in
6.10.5
References Updated Jul 13, 2026 · Source: OSV.dev | ||
6.2.1
patch
4 CVEs
CVE-2026-42088
PYSEC-2026-2245
GHSA-2wvh-87g2-89hr
May 04, 2026
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. Prior to version 7.0.0-rc3, the Script Runner widget allows users to execute Python and Ruby scripts directly from the openc3-COSMOS-script-runner-api container. Because all the docker containers share a network, users can execute specially crafted scripts to bypass the API permissions check and perform administrative actions, including reading and modifying data inside the Redis database, which can be used to read secrets and change COSMOS settings, as well as read and write to the buckets service, which holds configuration, log, and plugin files. These actions are normally only available from the Admin Console or with administrative privileges. Any user with permission to create and run scripts can connect to any service in the docker network. This issue has been patched in version 7.0.0-rc3. Affected versions
0.1.0
5.10.0
5.10.1
5.11.0
5.11.1
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
+ 40 more Show less
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.20.0
5.9.2b0
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.10.5
6.10.6
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
7.0.0rc2
7.0.0rc3
Fixed in
7.0.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-42086
PYSEC-2026-105
GHSA-ffq5-qpvf-xq7x
May 04, 2026
4.6
/ 10
Medium
Network
Low
Low
Required
Unchanged
Low
Low
None
OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. Prior to version 7.0.0, the Command Sender UI uses an unsafe eval() function on array-like command parameters, which allows a user-supplied payload to execute in the browser when sending a command. This creates a self-XSS risk because an attacker can trigger their own script execution in the victim’s session, if allowed to influence the array parameter input, for example via phishing. If successful, an attacker may read or modify data in the authenticated browser context, including session tokens in local storage. This issue has been patched in version 7.0.0. Affected versions
0.1.0
5.10.0
5.10.1
5.11.0
5.11.1
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
+ 40 more Show less
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.20.0
5.9.2b0
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.10.5
6.10.6
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
7.0.0rc2
7.0.0rc3
Fixed in
7.0.0
Updated May 20, 2026 · Source: OSV.dev
CVE-2026-42085
PYSEC-2026-2243
GHSA-4jvx-93h3-f45h
May 04, 2026
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
None
OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. Prior to versions 6.10.5 and 7.0.0-rc3, OpenC3 COSMOS contains a design flaw in the save_tool_config() function that allows saving tool configuration files at arbitrary locations inside the shared /plugins directory tree by supplying crafted configuration filenames. Although the implementation sufficiently mitigates standard path traversal attacks, by canonicalizing filename to an absolute path, all plugins share this same root directory. That enables users to create arbitrary file structures and overwrite existing configuration files within the shared /plugins directory. This issue has been patched in versions 6.10.5 and 7.0.0-rc3. Affected versions
0.1.0
5.10.0
5.10.1
5.11.0
5.11.1
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
+ 36 more Show less
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.20.0
5.9.2b0
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
Fixed in
6.10.5
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-42084
PYSEC-2026-2242
GHSA-wgx6-g857-jjf7
May 04, 2026
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. Prior to versions 6.10.5 and 7.0.0-rc3, the OpenC3 password change functionality allows a user to change their password without providing the old password, by accepting a valid session token instead. In assumed breach scenarios, this behaviour can be exploited by an attacker who has already obtained a valid session token, to gain persistence in hijacked account (including admin) and prevent legitimate users from accessing the account. This issue has been patched in versions 6.10.5 and 7.0.0-rc3. Affected versions
0.1.0
5.10.0
5.10.1
5.11.0
5.11.1
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
+ 36 more Show less
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.20.0
5.9.2b0
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
Fixed in
6.10.5
References Updated Jul 13, 2026 · Source: OSV.dev | ||
6.2.0
minor
4 CVEs
CVE-2026-42088
PYSEC-2026-2245
GHSA-2wvh-87g2-89hr
May 04, 2026
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. Prior to version 7.0.0-rc3, the Script Runner widget allows users to execute Python and Ruby scripts directly from the openc3-COSMOS-script-runner-api container. Because all the docker containers share a network, users can execute specially crafted scripts to bypass the API permissions check and perform administrative actions, including reading and modifying data inside the Redis database, which can be used to read secrets and change COSMOS settings, as well as read and write to the buckets service, which holds configuration, log, and plugin files. These actions are normally only available from the Admin Console or with administrative privileges. Any user with permission to create and run scripts can connect to any service in the docker network. This issue has been patched in version 7.0.0-rc3. Affected versions
0.1.0
5.10.0
5.10.1
5.11.0
5.11.1
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
+ 40 more Show less
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.20.0
5.9.2b0
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.10.5
6.10.6
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
7.0.0rc2
7.0.0rc3
Fixed in
7.0.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-42086
PYSEC-2026-105
GHSA-ffq5-qpvf-xq7x
May 04, 2026
4.6
/ 10
Medium
Network
Low
Low
Required
Unchanged
Low
Low
None
OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. Prior to version 7.0.0, the Command Sender UI uses an unsafe eval() function on array-like command parameters, which allows a user-supplied payload to execute in the browser when sending a command. This creates a self-XSS risk because an attacker can trigger their own script execution in the victim’s session, if allowed to influence the array parameter input, for example via phishing. If successful, an attacker may read or modify data in the authenticated browser context, including session tokens in local storage. This issue has been patched in version 7.0.0. Affected versions
0.1.0
5.10.0
5.10.1
5.11.0
5.11.1
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
+ 40 more Show less
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.20.0
5.9.2b0
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.10.5
6.10.6
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
7.0.0rc2
7.0.0rc3
Fixed in
7.0.0
Updated May 20, 2026 · Source: OSV.dev
CVE-2026-42085
PYSEC-2026-2243
GHSA-4jvx-93h3-f45h
May 04, 2026
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
None
OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. Prior to versions 6.10.5 and 7.0.0-rc3, OpenC3 COSMOS contains a design flaw in the save_tool_config() function that allows saving tool configuration files at arbitrary locations inside the shared /plugins directory tree by supplying crafted configuration filenames. Although the implementation sufficiently mitigates standard path traversal attacks, by canonicalizing filename to an absolute path, all plugins share this same root directory. That enables users to create arbitrary file structures and overwrite existing configuration files within the shared /plugins directory. This issue has been patched in versions 6.10.5 and 7.0.0-rc3. Affected versions
0.1.0
5.10.0
5.10.1
5.11.0
5.11.1
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
+ 36 more Show less
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.20.0
5.9.2b0
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
Fixed in
6.10.5
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-42084
PYSEC-2026-2242
GHSA-wgx6-g857-jjf7
May 04, 2026
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. Prior to versions 6.10.5 and 7.0.0-rc3, the OpenC3 password change functionality allows a user to change their password without providing the old password, by accepting a valid session token instead. In assumed breach scenarios, this behaviour can be exploited by an attacker who has already obtained a valid session token, to gain persistence in hijacked account (including admin) and prevent legitimate users from accessing the account. This issue has been patched in versions 6.10.5 and 7.0.0-rc3. Affected versions
0.1.0
5.10.0
5.10.1
5.11.0
5.11.1
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
+ 36 more Show less
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.20.0
5.9.2b0
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
Fixed in
6.10.5
References Updated Jul 13, 2026 · Source: OSV.dev | ||
6.1.0
minor
4 CVEs
CVE-2026-42088
PYSEC-2026-2245
GHSA-2wvh-87g2-89hr
May 04, 2026
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. Prior to version 7.0.0-rc3, the Script Runner widget allows users to execute Python and Ruby scripts directly from the openc3-COSMOS-script-runner-api container. Because all the docker containers share a network, users can execute specially crafted scripts to bypass the API permissions check and perform administrative actions, including reading and modifying data inside the Redis database, which can be used to read secrets and change COSMOS settings, as well as read and write to the buckets service, which holds configuration, log, and plugin files. These actions are normally only available from the Admin Console or with administrative privileges. Any user with permission to create and run scripts can connect to any service in the docker network. This issue has been patched in version 7.0.0-rc3. Affected versions
0.1.0
5.10.0
5.10.1
5.11.0
5.11.1
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
+ 40 more Show less
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.20.0
5.9.2b0
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.10.5
6.10.6
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
7.0.0rc2
7.0.0rc3
Fixed in
7.0.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-42086
PYSEC-2026-105
GHSA-ffq5-qpvf-xq7x
May 04, 2026
4.6
/ 10
Medium
Network
Low
Low
Required
Unchanged
Low
Low
None
OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. Prior to version 7.0.0, the Command Sender UI uses an unsafe eval() function on array-like command parameters, which allows a user-supplied payload to execute in the browser when sending a command. This creates a self-XSS risk because an attacker can trigger their own script execution in the victim’s session, if allowed to influence the array parameter input, for example via phishing. If successful, an attacker may read or modify data in the authenticated browser context, including session tokens in local storage. This issue has been patched in version 7.0.0. Affected versions
0.1.0
5.10.0
5.10.1
5.11.0
5.11.1
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
+ 40 more Show less
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.20.0
5.9.2b0
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.10.5
6.10.6
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
7.0.0rc2
7.0.0rc3
Fixed in
7.0.0
Updated May 20, 2026 · Source: OSV.dev
CVE-2026-42085
PYSEC-2026-2243
GHSA-4jvx-93h3-f45h
May 04, 2026
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
None
OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. Prior to versions 6.10.5 and 7.0.0-rc3, OpenC3 COSMOS contains a design flaw in the save_tool_config() function that allows saving tool configuration files at arbitrary locations inside the shared /plugins directory tree by supplying crafted configuration filenames. Although the implementation sufficiently mitigates standard path traversal attacks, by canonicalizing filename to an absolute path, all plugins share this same root directory. That enables users to create arbitrary file structures and overwrite existing configuration files within the shared /plugins directory. This issue has been patched in versions 6.10.5 and 7.0.0-rc3. Affected versions
0.1.0
5.10.0
5.10.1
5.11.0
5.11.1
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
+ 36 more Show less
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.20.0
5.9.2b0
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
Fixed in
6.10.5
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-42084
PYSEC-2026-2242
GHSA-wgx6-g857-jjf7
May 04, 2026
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. Prior to versions 6.10.5 and 7.0.0-rc3, the OpenC3 password change functionality allows a user to change their password without providing the old password, by accepting a valid session token instead. In assumed breach scenarios, this behaviour can be exploited by an attacker who has already obtained a valid session token, to gain persistence in hijacked account (including admin) and prevent legitimate users from accessing the account. This issue has been patched in versions 6.10.5 and 7.0.0-rc3. Affected versions
0.1.0
5.10.0
5.10.1
5.11.0
5.11.1
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
+ 36 more Show less
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.20.0
5.9.2b0
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
Fixed in
6.10.5
References Updated Jul 13, 2026 · Source: OSV.dev | ||
6.0.2
patch
4 CVEs
CVE-2026-42088
PYSEC-2026-2245
GHSA-2wvh-87g2-89hr
May 04, 2026
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. Prior to version 7.0.0-rc3, the Script Runner widget allows users to execute Python and Ruby scripts directly from the openc3-COSMOS-script-runner-api container. Because all the docker containers share a network, users can execute specially crafted scripts to bypass the API permissions check and perform administrative actions, including reading and modifying data inside the Redis database, which can be used to read secrets and change COSMOS settings, as well as read and write to the buckets service, which holds configuration, log, and plugin files. These actions are normally only available from the Admin Console or with administrative privileges. Any user with permission to create and run scripts can connect to any service in the docker network. This issue has been patched in version 7.0.0-rc3. Affected versions
0.1.0
5.10.0
5.10.1
5.11.0
5.11.1
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
+ 40 more Show less
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.20.0
5.9.2b0
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.10.5
6.10.6
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
7.0.0rc2
7.0.0rc3
Fixed in
7.0.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-42086
PYSEC-2026-105
GHSA-ffq5-qpvf-xq7x
May 04, 2026
4.6
/ 10
Medium
Network
Low
Low
Required
Unchanged
Low
Low
None
OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. Prior to version 7.0.0, the Command Sender UI uses an unsafe eval() function on array-like command parameters, which allows a user-supplied payload to execute in the browser when sending a command. This creates a self-XSS risk because an attacker can trigger their own script execution in the victim’s session, if allowed to influence the array parameter input, for example via phishing. If successful, an attacker may read or modify data in the authenticated browser context, including session tokens in local storage. This issue has been patched in version 7.0.0. Affected versions
0.1.0
5.10.0
5.10.1
5.11.0
5.11.1
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
+ 40 more Show less
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.20.0
5.9.2b0
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.10.5
6.10.6
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
7.0.0rc2
7.0.0rc3
Fixed in
7.0.0
Updated May 20, 2026 · Source: OSV.dev
CVE-2026-42085
PYSEC-2026-2243
GHSA-4jvx-93h3-f45h
May 04, 2026
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
None
OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. Prior to versions 6.10.5 and 7.0.0-rc3, OpenC3 COSMOS contains a design flaw in the save_tool_config() function that allows saving tool configuration files at arbitrary locations inside the shared /plugins directory tree by supplying crafted configuration filenames. Although the implementation sufficiently mitigates standard path traversal attacks, by canonicalizing filename to an absolute path, all plugins share this same root directory. That enables users to create arbitrary file structures and overwrite existing configuration files within the shared /plugins directory. This issue has been patched in versions 6.10.5 and 7.0.0-rc3. Affected versions
0.1.0
5.10.0
5.10.1
5.11.0
5.11.1
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
+ 36 more Show less
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.20.0
5.9.2b0
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
Fixed in
6.10.5
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-42084
PYSEC-2026-2242
GHSA-wgx6-g857-jjf7
May 04, 2026
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. Prior to versions 6.10.5 and 7.0.0-rc3, the OpenC3 password change functionality allows a user to change their password without providing the old password, by accepting a valid session token instead. In assumed breach scenarios, this behaviour can be exploited by an attacker who has already obtained a valid session token, to gain persistence in hijacked account (including admin) and prevent legitimate users from accessing the account. This issue has been patched in versions 6.10.5 and 7.0.0-rc3. Affected versions
0.1.0
5.10.0
5.10.1
5.11.0
5.11.1
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
+ 36 more Show less
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.20.0
5.9.2b0
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
Fixed in
6.10.5
References Updated Jul 13, 2026 · Source: OSV.dev | ||
6.0.1
patch
4 CVEs
CVE-2026-42088
PYSEC-2026-2245
GHSA-2wvh-87g2-89hr
May 04, 2026
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. Prior to version 7.0.0-rc3, the Script Runner widget allows users to execute Python and Ruby scripts directly from the openc3-COSMOS-script-runner-api container. Because all the docker containers share a network, users can execute specially crafted scripts to bypass the API permissions check and perform administrative actions, including reading and modifying data inside the Redis database, which can be used to read secrets and change COSMOS settings, as well as read and write to the buckets service, which holds configuration, log, and plugin files. These actions are normally only available from the Admin Console or with administrative privileges. Any user with permission to create and run scripts can connect to any service in the docker network. This issue has been patched in version 7.0.0-rc3. Affected versions
0.1.0
5.10.0
5.10.1
5.11.0
5.11.1
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
+ 40 more Show less
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.20.0
5.9.2b0
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.10.5
6.10.6
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
7.0.0rc2
7.0.0rc3
Fixed in
7.0.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-42086
PYSEC-2026-105
GHSA-ffq5-qpvf-xq7x
May 04, 2026
4.6
/ 10
Medium
Network
Low
Low
Required
Unchanged
Low
Low
None
OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. Prior to version 7.0.0, the Command Sender UI uses an unsafe eval() function on array-like command parameters, which allows a user-supplied payload to execute in the browser when sending a command. This creates a self-XSS risk because an attacker can trigger their own script execution in the victim’s session, if allowed to influence the array parameter input, for example via phishing. If successful, an attacker may read or modify data in the authenticated browser context, including session tokens in local storage. This issue has been patched in version 7.0.0. Affected versions
0.1.0
5.10.0
5.10.1
5.11.0
5.11.1
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
+ 40 more Show less
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.20.0
5.9.2b0
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.10.5
6.10.6
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
7.0.0rc2
7.0.0rc3
Fixed in
7.0.0
Updated May 20, 2026 · Source: OSV.dev
CVE-2026-42085
PYSEC-2026-2243
GHSA-4jvx-93h3-f45h
May 04, 2026
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
None
OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. Prior to versions 6.10.5 and 7.0.0-rc3, OpenC3 COSMOS contains a design flaw in the save_tool_config() function that allows saving tool configuration files at arbitrary locations inside the shared /plugins directory tree by supplying crafted configuration filenames. Although the implementation sufficiently mitigates standard path traversal attacks, by canonicalizing filename to an absolute path, all plugins share this same root directory. That enables users to create arbitrary file structures and overwrite existing configuration files within the shared /plugins directory. This issue has been patched in versions 6.10.5 and 7.0.0-rc3. Affected versions
0.1.0
5.10.0
5.10.1
5.11.0
5.11.1
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
+ 36 more Show less
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.20.0
5.9.2b0
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
Fixed in
6.10.5
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-42084
PYSEC-2026-2242
GHSA-wgx6-g857-jjf7
May 04, 2026
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. Prior to versions 6.10.5 and 7.0.0-rc3, the OpenC3 password change functionality allows a user to change their password without providing the old password, by accepting a valid session token instead. In assumed breach scenarios, this behaviour can be exploited by an attacker who has already obtained a valid session token, to gain persistence in hijacked account (including admin) and prevent legitimate users from accessing the account. This issue has been patched in versions 6.10.5 and 7.0.0-rc3. Affected versions
0.1.0
5.10.0
5.10.1
5.11.0
5.11.1
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
+ 36 more Show less
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.20.0
5.9.2b0
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
Fixed in
6.10.5
References Updated Jul 13, 2026 · Source: OSV.dev | ||
6.0.0
major
11 CVEs
CVE-2026-42088
PYSEC-2026-2245
GHSA-2wvh-87g2-89hr
May 04, 2026
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. Prior to version 7.0.0-rc3, the Script Runner widget allows users to execute Python and Ruby scripts directly from the openc3-COSMOS-script-runner-api container. Because all the docker containers share a network, users can execute specially crafted scripts to bypass the API permissions check and perform administrative actions, including reading and modifying data inside the Redis database, which can be used to read secrets and change COSMOS settings, as well as read and write to the buckets service, which holds configuration, log, and plugin files. These actions are normally only available from the Admin Console or with administrative privileges. Any user with permission to create and run scripts can connect to any service in the docker network. This issue has been patched in version 7.0.0-rc3. Affected versions
0.1.0
5.10.0
5.10.1
5.11.0
5.11.1
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
+ 40 more Show less
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.20.0
5.9.2b0
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.10.5
6.10.6
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
7.0.0rc2
7.0.0rc3
Fixed in
7.0.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-42086
PYSEC-2026-105
GHSA-ffq5-qpvf-xq7x
May 04, 2026
4.6
/ 10
Medium
Network
Low
Low
Required
Unchanged
Low
Low
None
OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. Prior to version 7.0.0, the Command Sender UI uses an unsafe eval() function on array-like command parameters, which allows a user-supplied payload to execute in the browser when sending a command. This creates a self-XSS risk because an attacker can trigger their own script execution in the victim’s session, if allowed to influence the array parameter input, for example via phishing. If successful, an attacker may read or modify data in the authenticated browser context, including session tokens in local storage. This issue has been patched in version 7.0.0. Affected versions
0.1.0
5.10.0
5.10.1
5.11.0
5.11.1
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
+ 40 more Show less
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.20.0
5.9.2b0
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.10.5
6.10.6
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
7.0.0rc2
7.0.0rc3
Fixed in
7.0.0
Updated May 20, 2026 · Source: OSV.dev
CVE-2026-42085
PYSEC-2026-2243
GHSA-4jvx-93h3-f45h
May 04, 2026
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
None
OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. Prior to versions 6.10.5 and 7.0.0-rc3, OpenC3 COSMOS contains a design flaw in the save_tool_config() function that allows saving tool configuration files at arbitrary locations inside the shared /plugins directory tree by supplying crafted configuration filenames. Although the implementation sufficiently mitigates standard path traversal attacks, by canonicalizing filename to an absolute path, all plugins share this same root directory. That enables users to create arbitrary file structures and overwrite existing configuration files within the shared /plugins directory. This issue has been patched in versions 6.10.5 and 7.0.0-rc3. Affected versions
0.1.0
5.10.0
5.10.1
5.11.0
5.11.1
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
+ 36 more Show less
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.20.0
5.9.2b0
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
Fixed in
6.10.5
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-42084
PYSEC-2026-2242
GHSA-wgx6-g857-jjf7
May 04, 2026
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. Prior to versions 6.10.5 and 7.0.0-rc3, the OpenC3 password change functionality allows a user to change their password without providing the old password, by accepting a valid session token instead. In assumed breach scenarios, this behaviour can be exploited by an attacker who has already obtained a valid session token, to gain persistence in hijacked account (including admin) and prevent legitimate users from accessing the account. This issue has been patched in versions 6.10.5 and 7.0.0-rc3. Affected versions
0.1.0
5.10.0
5.10.1
5.11.0
5.11.1
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
+ 36 more Show less
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.20.0
5.9.2b0
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
Fixed in
6.10.5
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-28389
PYSEC-2025-150
Jun 13, 2025
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Weak password requirements in OpenC3 COSMOS v6.0.0 allow attackers to bypass authentication via a brute force attack. Affected versions
0.1.0
5.10.0
5.10.1
5.11.0
5.11.1
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
+ 13 more Show less
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.20.0
5.9.2b0
6.0.0
References Updated May 21, 2026 · Source: OSV.dev
CVE-2025-28388
PYSEC-2025-258
Jun 13, 2025
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
OpenC3 COSMOS before v6.0.2 was discovered to contain hardcoded credentials for the Service Account. Affected versions
0.1.0
5.10.0
5.10.1
5.11.0
5.11.1
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
+ 13 more Show less
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.20.0
5.9.2b0
6.0.0
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-28386
PYSEC-2025-149
Jun 13, 2025
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
A remote code execution (RCE) vulnerability in the Plugin Management component of OpenC3 COSMOS v6.0.0 allows attackers to execute arbitrary code via uploading a crafted .txt file. Affected versions
0.1.0
5.10.0
5.10.1
5.11.0
5.11.1
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
+ 13 more Show less
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.20.0
5.9.2b0
6.0.0
References Updated May 21, 2026 · Source: OSV.dev
CVE-2025-28384
PYSEC-2025-257
GHSA-p67j-387g-75wc
Jun 13, 2025
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
None
An issue in the /script-api/scripts/ endpoint of OpenC3 COSMOS before 6.1.0 allows attackers to execute a directory traversal. Affected versions
0.1.0
5.10.0
5.10.1
5.11.0
5.11.1
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
+ 13 more Show less
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.20.0
5.9.2b0
6.0.0
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-28382
PYSEC-2025-256
GHSA-cf8v-5mrc-jv7f
Jun 13, 2025
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
An issue in the openc3-api/tables endpoint of OpenC3 COSMOS before 6.1.0 allows attackers to execute a directory traversal. Affected versions
0.1.0
5.10.0
5.10.1
5.11.0
5.11.1
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
+ 13 more Show less
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.20.0
5.9.2b0
6.0.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-28381
PYSEC-2025-255
Jun 13, 2025
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
A credential leak in OpenC3 COSMOS before v6.0.2 allows attackers to access service credentials as environment variables stored in all containers. Affected versions
0.1.0
5.10.0
5.10.1
5.11.0
5.11.1
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
+ 13 more Show less
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.20.0
5.9.2b0
6.0.0
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-28380
PYSEC-2025-254
Jun 13, 2025
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
A cross-site scripting (XSS) vulnerability in OpenC3 COSMOS before v6.0.2 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the URL parameter. Affected versions
0.1.0
5.10.0
5.10.1
5.11.0
5.11.1
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
+ 13 more Show less
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.20.0
5.9.2b0
6.0.0
References Updated Jul 13, 2026 · Source: OSV.dev | ||
5.20.0
minor
11 CVEs
CVE-2026-42088
PYSEC-2026-2245
GHSA-2wvh-87g2-89hr
May 04, 2026
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. Prior to version 7.0.0-rc3, the Script Runner widget allows users to execute Python and Ruby scripts directly from the openc3-COSMOS-script-runner-api container. Because all the docker containers share a network, users can execute specially crafted scripts to bypass the API permissions check and perform administrative actions, including reading and modifying data inside the Redis database, which can be used to read secrets and change COSMOS settings, as well as read and write to the buckets service, which holds configuration, log, and plugin files. These actions are normally only available from the Admin Console or with administrative privileges. Any user with permission to create and run scripts can connect to any service in the docker network. This issue has been patched in version 7.0.0-rc3. Affected versions
0.1.0
5.10.0
5.10.1
5.11.0
5.11.1
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
+ 40 more Show less
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.20.0
5.9.2b0
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.10.5
6.10.6
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
7.0.0rc2
7.0.0rc3
Fixed in
7.0.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-42086
PYSEC-2026-105
GHSA-ffq5-qpvf-xq7x
May 04, 2026
4.6
/ 10
Medium
Network
Low
Low
Required
Unchanged
Low
Low
None
OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. Prior to version 7.0.0, the Command Sender UI uses an unsafe eval() function on array-like command parameters, which allows a user-supplied payload to execute in the browser when sending a command. This creates a self-XSS risk because an attacker can trigger their own script execution in the victim’s session, if allowed to influence the array parameter input, for example via phishing. If successful, an attacker may read or modify data in the authenticated browser context, including session tokens in local storage. This issue has been patched in version 7.0.0. Affected versions
0.1.0
5.10.0
5.10.1
5.11.0
5.11.1
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
+ 40 more Show less
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.20.0
5.9.2b0
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.10.5
6.10.6
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
7.0.0rc2
7.0.0rc3
Fixed in
7.0.0
Updated May 20, 2026 · Source: OSV.dev
CVE-2026-42085
PYSEC-2026-2243
GHSA-4jvx-93h3-f45h
May 04, 2026
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
None
OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. Prior to versions 6.10.5 and 7.0.0-rc3, OpenC3 COSMOS contains a design flaw in the save_tool_config() function that allows saving tool configuration files at arbitrary locations inside the shared /plugins directory tree by supplying crafted configuration filenames. Although the implementation sufficiently mitigates standard path traversal attacks, by canonicalizing filename to an absolute path, all plugins share this same root directory. That enables users to create arbitrary file structures and overwrite existing configuration files within the shared /plugins directory. This issue has been patched in versions 6.10.5 and 7.0.0-rc3. Affected versions
0.1.0
5.10.0
5.10.1
5.11.0
5.11.1
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
+ 36 more Show less
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.20.0
5.9.2b0
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
Fixed in
6.10.5
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-42084
PYSEC-2026-2242
GHSA-wgx6-g857-jjf7
May 04, 2026
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. Prior to versions 6.10.5 and 7.0.0-rc3, the OpenC3 password change functionality allows a user to change their password without providing the old password, by accepting a valid session token instead. In assumed breach scenarios, this behaviour can be exploited by an attacker who has already obtained a valid session token, to gain persistence in hijacked account (including admin) and prevent legitimate users from accessing the account. This issue has been patched in versions 6.10.5 and 7.0.0-rc3. Affected versions
0.1.0
5.10.0
5.10.1
5.11.0
5.11.1
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
+ 36 more Show less
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.20.0
5.9.2b0
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
Fixed in
6.10.5
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-28389
PYSEC-2025-150
Jun 13, 2025
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Weak password requirements in OpenC3 COSMOS v6.0.0 allow attackers to bypass authentication via a brute force attack. Affected versions
0.1.0
5.10.0
5.10.1
5.11.0
5.11.1
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
+ 13 more Show less
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.20.0
5.9.2b0
6.0.0
References Updated May 21, 2026 · Source: OSV.dev
CVE-2025-28388
PYSEC-2025-258
Jun 13, 2025
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
OpenC3 COSMOS before v6.0.2 was discovered to contain hardcoded credentials for the Service Account. Affected versions
0.1.0
5.10.0
5.10.1
5.11.0
5.11.1
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
+ 13 more Show less
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.20.0
5.9.2b0
6.0.0
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-28386
PYSEC-2025-149
Jun 13, 2025
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
A remote code execution (RCE) vulnerability in the Plugin Management component of OpenC3 COSMOS v6.0.0 allows attackers to execute arbitrary code via uploading a crafted .txt file. Affected versions
0.1.0
5.10.0
5.10.1
5.11.0
5.11.1
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
+ 13 more Show less
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.20.0
5.9.2b0
6.0.0
References Updated May 21, 2026 · Source: OSV.dev
CVE-2025-28384
PYSEC-2025-257
GHSA-p67j-387g-75wc
Jun 13, 2025
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
None
An issue in the /script-api/scripts/ endpoint of OpenC3 COSMOS before 6.1.0 allows attackers to execute a directory traversal. Affected versions
0.1.0
5.10.0
5.10.1
5.11.0
5.11.1
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
+ 13 more Show less
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.20.0
5.9.2b0
6.0.0
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-28382
PYSEC-2025-256
GHSA-cf8v-5mrc-jv7f
Jun 13, 2025
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
An issue in the openc3-api/tables endpoint of OpenC3 COSMOS before 6.1.0 allows attackers to execute a directory traversal. Affected versions
0.1.0
5.10.0
5.10.1
5.11.0
5.11.1
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
+ 13 more Show less
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.20.0
5.9.2b0
6.0.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-28381
PYSEC-2025-255
Jun 13, 2025
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
A credential leak in OpenC3 COSMOS before v6.0.2 allows attackers to access service credentials as environment variables stored in all containers. Affected versions
0.1.0
5.10.0
5.10.1
5.11.0
5.11.1
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
+ 13 more Show less
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.20.0
5.9.2b0
6.0.0
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-28380
PYSEC-2025-254
Jun 13, 2025
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
A cross-site scripting (XSS) vulnerability in OpenC3 COSMOS before v6.0.2 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the URL parameter. Affected versions
0.1.0
5.10.0
5.10.1
5.11.0
5.11.1
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
+ 13 more Show less
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.20.0
5.9.2b0
6.0.0
References Updated Jul 13, 2026 · Source: OSV.dev | ||
5.19.0
minor
11 CVEs
CVE-2026-42088
PYSEC-2026-2245
GHSA-2wvh-87g2-89hr
May 04, 2026
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. Prior to version 7.0.0-rc3, the Script Runner widget allows users to execute Python and Ruby scripts directly from the openc3-COSMOS-script-runner-api container. Because all the docker containers share a network, users can execute specially crafted scripts to bypass the API permissions check and perform administrative actions, including reading and modifying data inside the Redis database, which can be used to read secrets and change COSMOS settings, as well as read and write to the buckets service, which holds configuration, log, and plugin files. These actions are normally only available from the Admin Console or with administrative privileges. Any user with permission to create and run scripts can connect to any service in the docker network. This issue has been patched in version 7.0.0-rc3. Affected versions
0.1.0
5.10.0
5.10.1
5.11.0
5.11.1
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
+ 40 more Show less
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.20.0
5.9.2b0
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.10.5
6.10.6
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
7.0.0rc2
7.0.0rc3
Fixed in
7.0.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-42086
PYSEC-2026-105
GHSA-ffq5-qpvf-xq7x
May 04, 2026
4.6
/ 10
Medium
Network
Low
Low
Required
Unchanged
Low
Low
None
OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. Prior to version 7.0.0, the Command Sender UI uses an unsafe eval() function on array-like command parameters, which allows a user-supplied payload to execute in the browser when sending a command. This creates a self-XSS risk because an attacker can trigger their own script execution in the victim’s session, if allowed to influence the array parameter input, for example via phishing. If successful, an attacker may read or modify data in the authenticated browser context, including session tokens in local storage. This issue has been patched in version 7.0.0. Affected versions
0.1.0
5.10.0
5.10.1
5.11.0
5.11.1
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
+ 40 more Show less
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.20.0
5.9.2b0
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.10.5
6.10.6
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
7.0.0rc2
7.0.0rc3
Fixed in
7.0.0
Updated May 20, 2026 · Source: OSV.dev
CVE-2026-42085
PYSEC-2026-2243
GHSA-4jvx-93h3-f45h
May 04, 2026
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
None
OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. Prior to versions 6.10.5 and 7.0.0-rc3, OpenC3 COSMOS contains a design flaw in the save_tool_config() function that allows saving tool configuration files at arbitrary locations inside the shared /plugins directory tree by supplying crafted configuration filenames. Although the implementation sufficiently mitigates standard path traversal attacks, by canonicalizing filename to an absolute path, all plugins share this same root directory. That enables users to create arbitrary file structures and overwrite existing configuration files within the shared /plugins directory. This issue has been patched in versions 6.10.5 and 7.0.0-rc3. Affected versions
0.1.0
5.10.0
5.10.1
5.11.0
5.11.1
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
+ 36 more Show less
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.20.0
5.9.2b0
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
Fixed in
6.10.5
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-42084
PYSEC-2026-2242
GHSA-wgx6-g857-jjf7
May 04, 2026
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. Prior to versions 6.10.5 and 7.0.0-rc3, the OpenC3 password change functionality allows a user to change their password without providing the old password, by accepting a valid session token instead. In assumed breach scenarios, this behaviour can be exploited by an attacker who has already obtained a valid session token, to gain persistence in hijacked account (including admin) and prevent legitimate users from accessing the account. This issue has been patched in versions 6.10.5 and 7.0.0-rc3. Affected versions
0.1.0
5.10.0
5.10.1
5.11.0
5.11.1
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
+ 36 more Show less
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.20.0
5.9.2b0
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
Fixed in
6.10.5
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-28389
PYSEC-2025-150
Jun 13, 2025
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Weak password requirements in OpenC3 COSMOS v6.0.0 allow attackers to bypass authentication via a brute force attack. Affected versions
0.1.0
5.10.0
5.10.1
5.11.0
5.11.1
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
+ 13 more Show less
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.20.0
5.9.2b0
6.0.0
References Updated May 21, 2026 · Source: OSV.dev
CVE-2025-28388
PYSEC-2025-258
Jun 13, 2025
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
OpenC3 COSMOS before v6.0.2 was discovered to contain hardcoded credentials for the Service Account. Affected versions
0.1.0
5.10.0
5.10.1
5.11.0
5.11.1
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
+ 13 more Show less
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.20.0
5.9.2b0
6.0.0
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-28386
PYSEC-2025-149
Jun 13, 2025
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
A remote code execution (RCE) vulnerability in the Plugin Management component of OpenC3 COSMOS v6.0.0 allows attackers to execute arbitrary code via uploading a crafted .txt file. Affected versions
0.1.0
5.10.0
5.10.1
5.11.0
5.11.1
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
+ 13 more Show less
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.20.0
5.9.2b0
6.0.0
References Updated May 21, 2026 · Source: OSV.dev
CVE-2025-28384
PYSEC-2025-257
GHSA-p67j-387g-75wc
Jun 13, 2025
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
None
An issue in the /script-api/scripts/ endpoint of OpenC3 COSMOS before 6.1.0 allows attackers to execute a directory traversal. Affected versions
0.1.0
5.10.0
5.10.1
5.11.0
5.11.1
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
+ 13 more Show less
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.20.0
5.9.2b0
6.0.0
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-28382
PYSEC-2025-256
GHSA-cf8v-5mrc-jv7f
Jun 13, 2025
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
An issue in the openc3-api/tables endpoint of OpenC3 COSMOS before 6.1.0 allows attackers to execute a directory traversal. Affected versions
0.1.0
5.10.0
5.10.1
5.11.0
5.11.1
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
+ 13 more Show less
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.20.0
5.9.2b0
6.0.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-28381
PYSEC-2025-255
Jun 13, 2025
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
A credential leak in OpenC3 COSMOS before v6.0.2 allows attackers to access service credentials as environment variables stored in all containers. Affected versions
0.1.0
5.10.0
5.10.1
5.11.0
5.11.1
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
+ 13 more Show less
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.20.0
5.9.2b0
6.0.0
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-28380
PYSEC-2025-254
Jun 13, 2025
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
A cross-site scripting (XSS) vulnerability in OpenC3 COSMOS before v6.0.2 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the URL parameter. Affected versions
0.1.0
5.10.0
5.10.1
5.11.0
5.11.1
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
+ 13 more Show less
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.20.0
5.9.2b0
6.0.0
References Updated Jul 13, 2026 · Source: OSV.dev | ||
5.18.0
minor
14 CVEs
CVE-2026-42088
PYSEC-2026-2245
GHSA-2wvh-87g2-89hr
May 04, 2026
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. Prior to version 7.0.0-rc3, the Script Runner widget allows users to execute Python and Ruby scripts directly from the openc3-COSMOS-script-runner-api container. Because all the docker containers share a network, users can execute specially crafted scripts to bypass the API permissions check and perform administrative actions, including reading and modifying data inside the Redis database, which can be used to read secrets and change COSMOS settings, as well as read and write to the buckets service, which holds configuration, log, and plugin files. These actions are normally only available from the Admin Console or with administrative privileges. Any user with permission to create and run scripts can connect to any service in the docker network. This issue has been patched in version 7.0.0-rc3. Affected versions
0.1.0
5.10.0
5.10.1
5.11.0
5.11.1
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
+ 40 more Show less
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.20.0
5.9.2b0
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.10.5
6.10.6
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
7.0.0rc2
7.0.0rc3
Fixed in
7.0.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-42086
PYSEC-2026-105
GHSA-ffq5-qpvf-xq7x
May 04, 2026
4.6
/ 10
Medium
Network
Low
Low
Required
Unchanged
Low
Low
None
OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. Prior to version 7.0.0, the Command Sender UI uses an unsafe eval() function on array-like command parameters, which allows a user-supplied payload to execute in the browser when sending a command. This creates a self-XSS risk because an attacker can trigger their own script execution in the victim’s session, if allowed to influence the array parameter input, for example via phishing. If successful, an attacker may read or modify data in the authenticated browser context, including session tokens in local storage. This issue has been patched in version 7.0.0. Affected versions
0.1.0
5.10.0
5.10.1
5.11.0
5.11.1
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
+ 40 more Show less
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.20.0
5.9.2b0
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.10.5
6.10.6
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
7.0.0rc2
7.0.0rc3
Fixed in
7.0.0
Updated May 20, 2026 · Source: OSV.dev
CVE-2026-42085
PYSEC-2026-2243
GHSA-4jvx-93h3-f45h
May 04, 2026
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
None
OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. Prior to versions 6.10.5 and 7.0.0-rc3, OpenC3 COSMOS contains a design flaw in the save_tool_config() function that allows saving tool configuration files at arbitrary locations inside the shared /plugins directory tree by supplying crafted configuration filenames. Although the implementation sufficiently mitigates standard path traversal attacks, by canonicalizing filename to an absolute path, all plugins share this same root directory. That enables users to create arbitrary file structures and overwrite existing configuration files within the shared /plugins directory. This issue has been patched in versions 6.10.5 and 7.0.0-rc3. Affected versions
0.1.0
5.10.0
5.10.1
5.11.0
5.11.1
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
+ 36 more Show less
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.20.0
5.9.2b0
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
Fixed in
6.10.5
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-42084
PYSEC-2026-2242
GHSA-wgx6-g857-jjf7
May 04, 2026
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. Prior to versions 6.10.5 and 7.0.0-rc3, the OpenC3 password change functionality allows a user to change their password without providing the old password, by accepting a valid session token instead. In assumed breach scenarios, this behaviour can be exploited by an attacker who has already obtained a valid session token, to gain persistence in hijacked account (including admin) and prevent legitimate users from accessing the account. This issue has been patched in versions 6.10.5 and 7.0.0-rc3. Affected versions
0.1.0
5.10.0
5.10.1
5.11.0
5.11.1
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
+ 36 more Show less
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.20.0
5.9.2b0
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
Fixed in
6.10.5
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-28389
PYSEC-2025-150
Jun 13, 2025
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Weak password requirements in OpenC3 COSMOS v6.0.0 allow attackers to bypass authentication via a brute force attack. Affected versions
0.1.0
5.10.0
5.10.1
5.11.0
5.11.1
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
+ 13 more Show less
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.20.0
5.9.2b0
6.0.0
References Updated May 21, 2026 · Source: OSV.dev
CVE-2025-28388
PYSEC-2025-258
Jun 13, 2025
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
OpenC3 COSMOS before v6.0.2 was discovered to contain hardcoded credentials for the Service Account. Affected versions
0.1.0
5.10.0
5.10.1
5.11.0
5.11.1
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
+ 13 more Show less
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.20.0
5.9.2b0
6.0.0
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-28386
PYSEC-2025-149
Jun 13, 2025
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
A remote code execution (RCE) vulnerability in the Plugin Management component of OpenC3 COSMOS v6.0.0 allows attackers to execute arbitrary code via uploading a crafted .txt file. Affected versions
0.1.0
5.10.0
5.10.1
5.11.0
5.11.1
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
+ 13 more Show less
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.20.0
5.9.2b0
6.0.0
References Updated May 21, 2026 · Source: OSV.dev
CVE-2025-28384
PYSEC-2025-257
GHSA-p67j-387g-75wc
Jun 13, 2025
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
None
An issue in the /script-api/scripts/ endpoint of OpenC3 COSMOS before 6.1.0 allows attackers to execute a directory traversal. Affected versions
0.1.0
5.10.0
5.10.1
5.11.0
5.11.1
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
+ 13 more Show less
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.20.0
5.9.2b0
6.0.0
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-28382
PYSEC-2025-256
GHSA-cf8v-5mrc-jv7f
Jun 13, 2025
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
An issue in the openc3-api/tables endpoint of OpenC3 COSMOS before 6.1.0 allows attackers to execute a directory traversal. Affected versions
0.1.0
5.10.0
5.10.1
5.11.0
5.11.1
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
+ 13 more Show less
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.20.0
5.9.2b0
6.0.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-28381
PYSEC-2025-255
Jun 13, 2025
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
A credential leak in OpenC3 COSMOS before v6.0.2 allows attackers to access service credentials as environment variables stored in all containers. Affected versions
0.1.0
5.10.0
5.10.1
5.11.0
5.11.1
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
+ 13 more Show less
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.20.0
5.9.2b0
6.0.0
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-28380
PYSEC-2025-254
Jun 13, 2025
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
A cross-site scripting (XSS) vulnerability in OpenC3 COSMOS before v6.0.2 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the URL parameter. Affected versions
0.1.0
5.10.0
5.10.1
5.11.0
5.11.1
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
+ 13 more Show less
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.20.0
5.9.2b0
6.0.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2024-43795
PYSEC-2024-100
GHSA-vfj8-5pj7-2f9g
Oct 02, 2024
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. The login functionality contains a reflected cross-site scripting (XSS) vulnerability. This vulnerability is fixed in 5.19.0. Note: This CVE only affects Open Source Edition, and not OpenC3 COSMOS Enterprise Edition. Affected versions
0.1.0
5.10.0
5.10.1
5.11.0
5.11.1
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
+ 10 more Show less
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.9.2b0
Fixed in
5.19.0
References Updated Oct 08, 2024 · Source: OSV.dev
CVE-2024-46977
PYSEC-2024-101
GHSA-8jxr-mccc-mwg8
Oct 02, 2024
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. A path traversal vulnerability inside of LocalMode's open_local_file method allows an authenticated user with adequate permissions to download any .txt via the ScreensController#show on the web server COSMOS is running on (depending on the file permissions). This vulnerability is fixed in 5.19.0. Affected versions
0.1.0
5.10.0
5.10.1
5.11.0
5.11.1
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
+ 10 more Show less
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.9.2b0
Fixed in
5.19.0
References Updated Oct 08, 2024 · Source: OSV.dev
CVE-2024-47529
PYSEC-2024-121
GHSA-4xqv-47rm-37mm
Oct 02, 2024
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
High
None
None
OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. OpenC3 COSMOS stores the password of a user unencrypted in the LocalStorage of a web browser. This makes the user password susceptible to exfiltration via Cross-site scripting (see GHSL-2024-128). This vulnerability is fixed in 5.19.0. This only affects Open Source edition, and not OpenC3 COSMOS Enterprise Edition. Affected versions
0.1.0
5.10.0
5.10.1
5.11.0
5.11.1
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
+ 10 more Show less
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.9.2b0
Fixed in
5.19.0
References Updated Nov 13, 2024 · Source: OSV.dev | ||
5.17.1
patch
14 CVEs
CVE-2026-42088
PYSEC-2026-2245
GHSA-2wvh-87g2-89hr
May 04, 2026
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. Prior to version 7.0.0-rc3, the Script Runner widget allows users to execute Python and Ruby scripts directly from the openc3-COSMOS-script-runner-api container. Because all the docker containers share a network, users can execute specially crafted scripts to bypass the API permissions check and perform administrative actions, including reading and modifying data inside the Redis database, which can be used to read secrets and change COSMOS settings, as well as read and write to the buckets service, which holds configuration, log, and plugin files. These actions are normally only available from the Admin Console or with administrative privileges. Any user with permission to create and run scripts can connect to any service in the docker network. This issue has been patched in version 7.0.0-rc3. Affected versions
0.1.0
5.10.0
5.10.1
5.11.0
5.11.1
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
+ 40 more Show less
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.20.0
5.9.2b0
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.10.5
6.10.6
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
7.0.0rc2
7.0.0rc3
Fixed in
7.0.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-42086
PYSEC-2026-105
GHSA-ffq5-qpvf-xq7x
May 04, 2026
4.6
/ 10
Medium
Network
Low
Low
Required
Unchanged
Low
Low
None
OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. Prior to version 7.0.0, the Command Sender UI uses an unsafe eval() function on array-like command parameters, which allows a user-supplied payload to execute in the browser when sending a command. This creates a self-XSS risk because an attacker can trigger their own script execution in the victim’s session, if allowed to influence the array parameter input, for example via phishing. If successful, an attacker may read or modify data in the authenticated browser context, including session tokens in local storage. This issue has been patched in version 7.0.0. Affected versions
0.1.0
5.10.0
5.10.1
5.11.0
5.11.1
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
+ 40 more Show less
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.20.0
5.9.2b0
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.10.5
6.10.6
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
7.0.0rc2
7.0.0rc3
Fixed in
7.0.0
Updated May 20, 2026 · Source: OSV.dev
CVE-2026-42085
PYSEC-2026-2243
GHSA-4jvx-93h3-f45h
May 04, 2026
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
None
OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. Prior to versions 6.10.5 and 7.0.0-rc3, OpenC3 COSMOS contains a design flaw in the save_tool_config() function that allows saving tool configuration files at arbitrary locations inside the shared /plugins directory tree by supplying crafted configuration filenames. Although the implementation sufficiently mitigates standard path traversal attacks, by canonicalizing filename to an absolute path, all plugins share this same root directory. That enables users to create arbitrary file structures and overwrite existing configuration files within the shared /plugins directory. This issue has been patched in versions 6.10.5 and 7.0.0-rc3. Affected versions
0.1.0
5.10.0
5.10.1
5.11.0
5.11.1
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
+ 36 more Show less
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.20.0
5.9.2b0
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
Fixed in
6.10.5
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-42084
PYSEC-2026-2242
GHSA-wgx6-g857-jjf7
May 04, 2026
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. Prior to versions 6.10.5 and 7.0.0-rc3, the OpenC3 password change functionality allows a user to change their password without providing the old password, by accepting a valid session token instead. In assumed breach scenarios, this behaviour can be exploited by an attacker who has already obtained a valid session token, to gain persistence in hijacked account (including admin) and prevent legitimate users from accessing the account. This issue has been patched in versions 6.10.5 and 7.0.0-rc3. Affected versions
0.1.0
5.10.0
5.10.1
5.11.0
5.11.1
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
+ 36 more Show less
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.20.0
5.9.2b0
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
Fixed in
6.10.5
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-28389
PYSEC-2025-150
Jun 13, 2025
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Weak password requirements in OpenC3 COSMOS v6.0.0 allow attackers to bypass authentication via a brute force attack. Affected versions
0.1.0
5.10.0
5.10.1
5.11.0
5.11.1
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
+ 13 more Show less
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.20.0
5.9.2b0
6.0.0
References Updated May 21, 2026 · Source: OSV.dev
CVE-2025-28388
PYSEC-2025-258
Jun 13, 2025
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
OpenC3 COSMOS before v6.0.2 was discovered to contain hardcoded credentials for the Service Account. Affected versions
0.1.0
5.10.0
5.10.1
5.11.0
5.11.1
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
+ 13 more Show less
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.20.0
5.9.2b0
6.0.0
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-28386
PYSEC-2025-149
Jun 13, 2025
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
A remote code execution (RCE) vulnerability in the Plugin Management component of OpenC3 COSMOS v6.0.0 allows attackers to execute arbitrary code via uploading a crafted .txt file. Affected versions
0.1.0
5.10.0
5.10.1
5.11.0
5.11.1
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
+ 13 more Show less
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.20.0
5.9.2b0
6.0.0
References Updated May 21, 2026 · Source: OSV.dev
CVE-2025-28384
PYSEC-2025-257
GHSA-p67j-387g-75wc
Jun 13, 2025
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
None
An issue in the /script-api/scripts/ endpoint of OpenC3 COSMOS before 6.1.0 allows attackers to execute a directory traversal. Affected versions
0.1.0
5.10.0
5.10.1
5.11.0
5.11.1
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
+ 13 more Show less
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.20.0
5.9.2b0
6.0.0
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-28382
PYSEC-2025-256
GHSA-cf8v-5mrc-jv7f
Jun 13, 2025
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
An issue in the openc3-api/tables endpoint of OpenC3 COSMOS before 6.1.0 allows attackers to execute a directory traversal. Affected versions
0.1.0
5.10.0
5.10.1
5.11.0
5.11.1
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
+ 13 more Show less
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.20.0
5.9.2b0
6.0.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-28381
PYSEC-2025-255
Jun 13, 2025
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
A credential leak in OpenC3 COSMOS before v6.0.2 allows attackers to access service credentials as environment variables stored in all containers. Affected versions
0.1.0
5.10.0
5.10.1
5.11.0
5.11.1
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
+ 13 more Show less
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.20.0
5.9.2b0
6.0.0
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-28380
PYSEC-2025-254
Jun 13, 2025
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
A cross-site scripting (XSS) vulnerability in OpenC3 COSMOS before v6.0.2 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the URL parameter. Affected versions
0.1.0
5.10.0
5.10.1
5.11.0
5.11.1
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
+ 13 more Show less
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.20.0
5.9.2b0
6.0.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2024-43795
PYSEC-2024-100
GHSA-vfj8-5pj7-2f9g
Oct 02, 2024
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. The login functionality contains a reflected cross-site scripting (XSS) vulnerability. This vulnerability is fixed in 5.19.0. Note: This CVE only affects Open Source Edition, and not OpenC3 COSMOS Enterprise Edition. Affected versions
0.1.0
5.10.0
5.10.1
5.11.0
5.11.1
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
+ 10 more Show less
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.9.2b0
Fixed in
5.19.0
References Updated Oct 08, 2024 · Source: OSV.dev
CVE-2024-46977
PYSEC-2024-101
GHSA-8jxr-mccc-mwg8
Oct 02, 2024
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. A path traversal vulnerability inside of LocalMode's open_local_file method allows an authenticated user with adequate permissions to download any .txt via the ScreensController#show on the web server COSMOS is running on (depending on the file permissions). This vulnerability is fixed in 5.19.0. Affected versions
0.1.0
5.10.0
5.10.1
5.11.0
5.11.1
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
+ 10 more Show less
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.9.2b0
Fixed in
5.19.0
References Updated Oct 08, 2024 · Source: OSV.dev
CVE-2024-47529
PYSEC-2024-121
GHSA-4xqv-47rm-37mm
Oct 02, 2024
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
High
None
None
OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. OpenC3 COSMOS stores the password of a user unencrypted in the LocalStorage of a web browser. This makes the user password susceptible to exfiltration via Cross-site scripting (see GHSL-2024-128). This vulnerability is fixed in 5.19.0. This only affects Open Source edition, and not OpenC3 COSMOS Enterprise Edition. Affected versions
0.1.0
5.10.0
5.10.1
5.11.0
5.11.1
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
+ 10 more Show less
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.9.2b0
Fixed in
5.19.0
References Updated Nov 13, 2024 · Source: OSV.dev | ||
5.17.0
minor
14 CVEs
CVE-2026-42088
PYSEC-2026-2245
GHSA-2wvh-87g2-89hr
May 04, 2026
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. Prior to version 7.0.0-rc3, the Script Runner widget allows users to execute Python and Ruby scripts directly from the openc3-COSMOS-script-runner-api container. Because all the docker containers share a network, users can execute specially crafted scripts to bypass the API permissions check and perform administrative actions, including reading and modifying data inside the Redis database, which can be used to read secrets and change COSMOS settings, as well as read and write to the buckets service, which holds configuration, log, and plugin files. These actions are normally only available from the Admin Console or with administrative privileges. Any user with permission to create and run scripts can connect to any service in the docker network. This issue has been patched in version 7.0.0-rc3. Affected versions
0.1.0
5.10.0
5.10.1
5.11.0
5.11.1
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
+ 40 more Show less
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.20.0
5.9.2b0
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.10.5
6.10.6
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
7.0.0rc2
7.0.0rc3
Fixed in
7.0.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-42086
PYSEC-2026-105
GHSA-ffq5-qpvf-xq7x
May 04, 2026
4.6
/ 10
Medium
Network
Low
Low
Required
Unchanged
Low
Low
None
OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. Prior to version 7.0.0, the Command Sender UI uses an unsafe eval() function on array-like command parameters, which allows a user-supplied payload to execute in the browser when sending a command. This creates a self-XSS risk because an attacker can trigger their own script execution in the victim’s session, if allowed to influence the array parameter input, for example via phishing. If successful, an attacker may read or modify data in the authenticated browser context, including session tokens in local storage. This issue has been patched in version 7.0.0. Affected versions
0.1.0
5.10.0
5.10.1
5.11.0
5.11.1
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
+ 40 more Show less
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.20.0
5.9.2b0
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.10.5
6.10.6
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
7.0.0rc2
7.0.0rc3
Fixed in
7.0.0
Updated May 20, 2026 · Source: OSV.dev
CVE-2026-42085
PYSEC-2026-2243
GHSA-4jvx-93h3-f45h
May 04, 2026
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
None
OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. Prior to versions 6.10.5 and 7.0.0-rc3, OpenC3 COSMOS contains a design flaw in the save_tool_config() function that allows saving tool configuration files at arbitrary locations inside the shared /plugins directory tree by supplying crafted configuration filenames. Although the implementation sufficiently mitigates standard path traversal attacks, by canonicalizing filename to an absolute path, all plugins share this same root directory. That enables users to create arbitrary file structures and overwrite existing configuration files within the shared /plugins directory. This issue has been patched in versions 6.10.5 and 7.0.0-rc3. Affected versions
0.1.0
5.10.0
5.10.1
5.11.0
5.11.1
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
+ 36 more Show less
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.20.0
5.9.2b0
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
Fixed in
6.10.5
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-42084
PYSEC-2026-2242
GHSA-wgx6-g857-jjf7
May 04, 2026
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. Prior to versions 6.10.5 and 7.0.0-rc3, the OpenC3 password change functionality allows a user to change their password without providing the old password, by accepting a valid session token instead. In assumed breach scenarios, this behaviour can be exploited by an attacker who has already obtained a valid session token, to gain persistence in hijacked account (including admin) and prevent legitimate users from accessing the account. This issue has been patched in versions 6.10.5 and 7.0.0-rc3. Affected versions
0.1.0
5.10.0
5.10.1
5.11.0
5.11.1
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
+ 36 more Show less
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.20.0
5.9.2b0
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
Fixed in
6.10.5
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-28389
PYSEC-2025-150
Jun 13, 2025
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Weak password requirements in OpenC3 COSMOS v6.0.0 allow attackers to bypass authentication via a brute force attack. Affected versions
0.1.0
5.10.0
5.10.1
5.11.0
5.11.1
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
+ 13 more Show less
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.20.0
5.9.2b0
6.0.0
References Updated May 21, 2026 · Source: OSV.dev
CVE-2025-28388
PYSEC-2025-258
Jun 13, 2025
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
OpenC3 COSMOS before v6.0.2 was discovered to contain hardcoded credentials for the Service Account. Affected versions
0.1.0
5.10.0
5.10.1
5.11.0
5.11.1
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
+ 13 more Show less
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.20.0
5.9.2b0
6.0.0
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-28386
PYSEC-2025-149
Jun 13, 2025
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
A remote code execution (RCE) vulnerability in the Plugin Management component of OpenC3 COSMOS v6.0.0 allows attackers to execute arbitrary code via uploading a crafted .txt file. Affected versions
0.1.0
5.10.0
5.10.1
5.11.0
5.11.1
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
+ 13 more Show less
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.20.0
5.9.2b0
6.0.0
References Updated May 21, 2026 · Source: OSV.dev
CVE-2025-28384
PYSEC-2025-257
GHSA-p67j-387g-75wc
Jun 13, 2025
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
None
An issue in the /script-api/scripts/ endpoint of OpenC3 COSMOS before 6.1.0 allows attackers to execute a directory traversal. Affected versions
0.1.0
5.10.0
5.10.1
5.11.0
5.11.1
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
+ 13 more Show less
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.20.0
5.9.2b0
6.0.0
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-28382
PYSEC-2025-256
GHSA-cf8v-5mrc-jv7f
Jun 13, 2025
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
An issue in the openc3-api/tables endpoint of OpenC3 COSMOS before 6.1.0 allows attackers to execute a directory traversal. Affected versions
0.1.0
5.10.0
5.10.1
5.11.0
5.11.1
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
+ 13 more Show less
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.20.0
5.9.2b0
6.0.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-28381
PYSEC-2025-255
Jun 13, 2025
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
A credential leak in OpenC3 COSMOS before v6.0.2 allows attackers to access service credentials as environment variables stored in all containers. Affected versions
0.1.0
5.10.0
5.10.1
5.11.0
5.11.1
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
+ 13 more Show less
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.20.0
5.9.2b0
6.0.0
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-28380
PYSEC-2025-254
Jun 13, 2025
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
A cross-site scripting (XSS) vulnerability in OpenC3 COSMOS before v6.0.2 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the URL parameter. Affected versions
0.1.0
5.10.0
5.10.1
5.11.0
5.11.1
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
+ 13 more Show less
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.20.0
5.9.2b0
6.0.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2024-43795
PYSEC-2024-100
GHSA-vfj8-5pj7-2f9g
Oct 02, 2024
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. The login functionality contains a reflected cross-site scripting (XSS) vulnerability. This vulnerability is fixed in 5.19.0. Note: This CVE only affects Open Source Edition, and not OpenC3 COSMOS Enterprise Edition. Affected versions
0.1.0
5.10.0
5.10.1
5.11.0
5.11.1
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
+ 10 more Show less
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.9.2b0
Fixed in
5.19.0
References Updated Oct 08, 2024 · Source: OSV.dev
CVE-2024-46977
PYSEC-2024-101
GHSA-8jxr-mccc-mwg8
Oct 02, 2024
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. A path traversal vulnerability inside of LocalMode's open_local_file method allows an authenticated user with adequate permissions to download any .txt via the ScreensController#show on the web server COSMOS is running on (depending on the file permissions). This vulnerability is fixed in 5.19.0. Affected versions
0.1.0
5.10.0
5.10.1
5.11.0
5.11.1
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
+ 10 more Show less
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.9.2b0
Fixed in
5.19.0
References Updated Oct 08, 2024 · Source: OSV.dev
CVE-2024-47529
PYSEC-2024-121
GHSA-4xqv-47rm-37mm
Oct 02, 2024
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
High
None
None
OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. OpenC3 COSMOS stores the password of a user unencrypted in the LocalStorage of a web browser. This makes the user password susceptible to exfiltration via Cross-site scripting (see GHSL-2024-128). This vulnerability is fixed in 5.19.0. This only affects Open Source edition, and not OpenC3 COSMOS Enterprise Edition. Affected versions
0.1.0
5.10.0
5.10.1
5.11.0
5.11.1
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
+ 10 more Show less
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.9.2b0
Fixed in
5.19.0
References Updated Nov 13, 2024 · Source: OSV.dev | ||
5.16.2
patch
14 CVEs
CVE-2026-42088
PYSEC-2026-2245
GHSA-2wvh-87g2-89hr
May 04, 2026
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. Prior to version 7.0.0-rc3, the Script Runner widget allows users to execute Python and Ruby scripts directly from the openc3-COSMOS-script-runner-api container. Because all the docker containers share a network, users can execute specially crafted scripts to bypass the API permissions check and perform administrative actions, including reading and modifying data inside the Redis database, which can be used to read secrets and change COSMOS settings, as well as read and write to the buckets service, which holds configuration, log, and plugin files. These actions are normally only available from the Admin Console or with administrative privileges. Any user with permission to create and run scripts can connect to any service in the docker network. This issue has been patched in version 7.0.0-rc3. Affected versions
0.1.0
5.10.0
5.10.1
5.11.0
5.11.1
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
+ 40 more Show less
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.20.0
5.9.2b0
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.10.5
6.10.6
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
7.0.0rc2
7.0.0rc3
Fixed in
7.0.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-42086
PYSEC-2026-105
GHSA-ffq5-qpvf-xq7x
May 04, 2026
4.6
/ 10
Medium
Network
Low
Low
Required
Unchanged
Low
Low
None
OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. Prior to version 7.0.0, the Command Sender UI uses an unsafe eval() function on array-like command parameters, which allows a user-supplied payload to execute in the browser when sending a command. This creates a self-XSS risk because an attacker can trigger their own script execution in the victim’s session, if allowed to influence the array parameter input, for example via phishing. If successful, an attacker may read or modify data in the authenticated browser context, including session tokens in local storage. This issue has been patched in version 7.0.0. Affected versions
0.1.0
5.10.0
5.10.1
5.11.0
5.11.1
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
+ 40 more Show less
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.20.0
5.9.2b0
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.10.5
6.10.6
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
7.0.0rc2
7.0.0rc3
Fixed in
7.0.0
Updated May 20, 2026 · Source: OSV.dev
CVE-2026-42085
PYSEC-2026-2243
GHSA-4jvx-93h3-f45h
May 04, 2026
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
None
OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. Prior to versions 6.10.5 and 7.0.0-rc3, OpenC3 COSMOS contains a design flaw in the save_tool_config() function that allows saving tool configuration files at arbitrary locations inside the shared /plugins directory tree by supplying crafted configuration filenames. Although the implementation sufficiently mitigates standard path traversal attacks, by canonicalizing filename to an absolute path, all plugins share this same root directory. That enables users to create arbitrary file structures and overwrite existing configuration files within the shared /plugins directory. This issue has been patched in versions 6.10.5 and 7.0.0-rc3. Affected versions
0.1.0
5.10.0
5.10.1
5.11.0
5.11.1
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
+ 36 more Show less
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.20.0
5.9.2b0
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
Fixed in
6.10.5
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-42084
PYSEC-2026-2242
GHSA-wgx6-g857-jjf7
May 04, 2026
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. Prior to versions 6.10.5 and 7.0.0-rc3, the OpenC3 password change functionality allows a user to change their password without providing the old password, by accepting a valid session token instead. In assumed breach scenarios, this behaviour can be exploited by an attacker who has already obtained a valid session token, to gain persistence in hijacked account (including admin) and prevent legitimate users from accessing the account. This issue has been patched in versions 6.10.5 and 7.0.0-rc3. Affected versions
0.1.0
5.10.0
5.10.1
5.11.0
5.11.1
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
+ 36 more Show less
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.20.0
5.9.2b0
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
Fixed in
6.10.5
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-28389
PYSEC-2025-150
Jun 13, 2025
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Weak password requirements in OpenC3 COSMOS v6.0.0 allow attackers to bypass authentication via a brute force attack. Affected versions
0.1.0
5.10.0
5.10.1
5.11.0
5.11.1
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
+ 13 more Show less
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.20.0
5.9.2b0
6.0.0
References Updated May 21, 2026 · Source: OSV.dev
CVE-2025-28388
PYSEC-2025-258
Jun 13, 2025
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
OpenC3 COSMOS before v6.0.2 was discovered to contain hardcoded credentials for the Service Account. Affected versions
0.1.0
5.10.0
5.10.1
5.11.0
5.11.1
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
+ 13 more Show less
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.20.0
5.9.2b0
6.0.0
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-28386
PYSEC-2025-149
Jun 13, 2025
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
A remote code execution (RCE) vulnerability in the Plugin Management component of OpenC3 COSMOS v6.0.0 allows attackers to execute arbitrary code via uploading a crafted .txt file. Affected versions
0.1.0
5.10.0
5.10.1
5.11.0
5.11.1
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
+ 13 more Show less
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.20.0
5.9.2b0
6.0.0
References Updated May 21, 2026 · Source: OSV.dev
CVE-2025-28384
PYSEC-2025-257
GHSA-p67j-387g-75wc
Jun 13, 2025
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
None
An issue in the /script-api/scripts/ endpoint of OpenC3 COSMOS before 6.1.0 allows attackers to execute a directory traversal. Affected versions
0.1.0
5.10.0
5.10.1
5.11.0
5.11.1
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
+ 13 more Show less
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.20.0
5.9.2b0
6.0.0
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-28382
PYSEC-2025-256
GHSA-cf8v-5mrc-jv7f
Jun 13, 2025
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
An issue in the openc3-api/tables endpoint of OpenC3 COSMOS before 6.1.0 allows attackers to execute a directory traversal. Affected versions
0.1.0
5.10.0
5.10.1
5.11.0
5.11.1
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
+ 13 more Show less
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.20.0
5.9.2b0
6.0.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-28381
PYSEC-2025-255
Jun 13, 2025
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
A credential leak in OpenC3 COSMOS before v6.0.2 allows attackers to access service credentials as environment variables stored in all containers. Affected versions
0.1.0
5.10.0
5.10.1
5.11.0
5.11.1
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
+ 13 more Show less
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.20.0
5.9.2b0
6.0.0
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-28380
PYSEC-2025-254
Jun 13, 2025
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
A cross-site scripting (XSS) vulnerability in OpenC3 COSMOS before v6.0.2 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the URL parameter. Affected versions
0.1.0
5.10.0
5.10.1
5.11.0
5.11.1
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
+ 13 more Show less
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.20.0
5.9.2b0
6.0.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2024-43795
PYSEC-2024-100
GHSA-vfj8-5pj7-2f9g
Oct 02, 2024
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. The login functionality contains a reflected cross-site scripting (XSS) vulnerability. This vulnerability is fixed in 5.19.0. Note: This CVE only affects Open Source Edition, and not OpenC3 COSMOS Enterprise Edition. Affected versions
0.1.0
5.10.0
5.10.1
5.11.0
5.11.1
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
+ 10 more Show less
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.9.2b0
Fixed in
5.19.0
References Updated Oct 08, 2024 · Source: OSV.dev
CVE-2024-46977
PYSEC-2024-101
GHSA-8jxr-mccc-mwg8
Oct 02, 2024
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. A path traversal vulnerability inside of LocalMode's open_local_file method allows an authenticated user with adequate permissions to download any .txt via the ScreensController#show on the web server COSMOS is running on (depending on the file permissions). This vulnerability is fixed in 5.19.0. Affected versions
0.1.0
5.10.0
5.10.1
5.11.0
5.11.1
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
+ 10 more Show less
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.9.2b0
Fixed in
5.19.0
References Updated Oct 08, 2024 · Source: OSV.dev
CVE-2024-47529
PYSEC-2024-121
GHSA-4xqv-47rm-37mm
Oct 02, 2024
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
High
None
None
OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. OpenC3 COSMOS stores the password of a user unencrypted in the LocalStorage of a web browser. This makes the user password susceptible to exfiltration via Cross-site scripting (see GHSL-2024-128). This vulnerability is fixed in 5.19.0. This only affects Open Source edition, and not OpenC3 COSMOS Enterprise Edition. Affected versions
0.1.0
5.10.0
5.10.1
5.11.0
5.11.1
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
+ 10 more Show less
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.9.2b0
Fixed in
5.19.0
References Updated Nov 13, 2024 · Source: OSV.dev | ||
0.1.0
initial
14 CVEs
CVE-2026-42088
PYSEC-2026-2245
GHSA-2wvh-87g2-89hr
May 04, 2026
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. Prior to version 7.0.0-rc3, the Script Runner widget allows users to execute Python and Ruby scripts directly from the openc3-COSMOS-script-runner-api container. Because all the docker containers share a network, users can execute specially crafted scripts to bypass the API permissions check and perform administrative actions, including reading and modifying data inside the Redis database, which can be used to read secrets and change COSMOS settings, as well as read and write to the buckets service, which holds configuration, log, and plugin files. These actions are normally only available from the Admin Console or with administrative privileges. Any user with permission to create and run scripts can connect to any service in the docker network. This issue has been patched in version 7.0.0-rc3. Affected versions
0.1.0
5.10.0
5.10.1
5.11.0
5.11.1
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
+ 40 more Show less
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.20.0
5.9.2b0
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.10.5
6.10.6
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
7.0.0rc2
7.0.0rc3
Fixed in
7.0.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-42086
PYSEC-2026-105
GHSA-ffq5-qpvf-xq7x
May 04, 2026
4.6
/ 10
Medium
Network
Low
Low
Required
Unchanged
Low
Low
None
OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. Prior to version 7.0.0, the Command Sender UI uses an unsafe eval() function on array-like command parameters, which allows a user-supplied payload to execute in the browser when sending a command. This creates a self-XSS risk because an attacker can trigger their own script execution in the victim’s session, if allowed to influence the array parameter input, for example via phishing. If successful, an attacker may read or modify data in the authenticated browser context, including session tokens in local storage. This issue has been patched in version 7.0.0. Affected versions
0.1.0
5.10.0
5.10.1
5.11.0
5.11.1
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
+ 40 more Show less
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.20.0
5.9.2b0
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.10.5
6.10.6
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
7.0.0rc2
7.0.0rc3
Fixed in
7.0.0
Updated May 20, 2026 · Source: OSV.dev
CVE-2026-42085
PYSEC-2026-2243
GHSA-4jvx-93h3-f45h
May 04, 2026
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
None
OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. Prior to versions 6.10.5 and 7.0.0-rc3, OpenC3 COSMOS contains a design flaw in the save_tool_config() function that allows saving tool configuration files at arbitrary locations inside the shared /plugins directory tree by supplying crafted configuration filenames. Although the implementation sufficiently mitigates standard path traversal attacks, by canonicalizing filename to an absolute path, all plugins share this same root directory. That enables users to create arbitrary file structures and overwrite existing configuration files within the shared /plugins directory. This issue has been patched in versions 6.10.5 and 7.0.0-rc3. Affected versions
0.1.0
5.10.0
5.10.1
5.11.0
5.11.1
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
+ 36 more Show less
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.20.0
5.9.2b0
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
Fixed in
6.10.5
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-42084
PYSEC-2026-2242
GHSA-wgx6-g857-jjf7
May 04, 2026
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. Prior to versions 6.10.5 and 7.0.0-rc3, the OpenC3 password change functionality allows a user to change their password without providing the old password, by accepting a valid session token instead. In assumed breach scenarios, this behaviour can be exploited by an attacker who has already obtained a valid session token, to gain persistence in hijacked account (including admin) and prevent legitimate users from accessing the account. This issue has been patched in versions 6.10.5 and 7.0.0-rc3. Affected versions
0.1.0
5.10.0
5.10.1
5.11.0
5.11.1
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
+ 36 more Show less
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.20.0
5.9.2b0
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
Fixed in
6.10.5
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-28389
PYSEC-2025-150
Jun 13, 2025
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Weak password requirements in OpenC3 COSMOS v6.0.0 allow attackers to bypass authentication via a brute force attack. Affected versions
0.1.0
5.10.0
5.10.1
5.11.0
5.11.1
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
+ 13 more Show less
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.20.0
5.9.2b0
6.0.0
References Updated May 21, 2026 · Source: OSV.dev
CVE-2025-28388
PYSEC-2025-258
Jun 13, 2025
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
OpenC3 COSMOS before v6.0.2 was discovered to contain hardcoded credentials for the Service Account. Affected versions
0.1.0
5.10.0
5.10.1
5.11.0
5.11.1
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
+ 13 more Show less
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.20.0
5.9.2b0
6.0.0
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-28386
PYSEC-2025-149
Jun 13, 2025
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
A remote code execution (RCE) vulnerability in the Plugin Management component of OpenC3 COSMOS v6.0.0 allows attackers to execute arbitrary code via uploading a crafted .txt file. Affected versions
0.1.0
5.10.0
5.10.1
5.11.0
5.11.1
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
+ 13 more Show less
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.20.0
5.9.2b0
6.0.0
References Updated May 21, 2026 · Source: OSV.dev
CVE-2025-28384
PYSEC-2025-257
GHSA-p67j-387g-75wc
Jun 13, 2025
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
None
An issue in the /script-api/scripts/ endpoint of OpenC3 COSMOS before 6.1.0 allows attackers to execute a directory traversal. Affected versions
0.1.0
5.10.0
5.10.1
5.11.0
5.11.1
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
+ 13 more Show less
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.20.0
5.9.2b0
6.0.0
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-28382
PYSEC-2025-256
GHSA-cf8v-5mrc-jv7f
Jun 13, 2025
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
An issue in the openc3-api/tables endpoint of OpenC3 COSMOS before 6.1.0 allows attackers to execute a directory traversal. Affected versions
0.1.0
5.10.0
5.10.1
5.11.0
5.11.1
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
+ 13 more Show less
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.20.0
5.9.2b0
6.0.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-28381
PYSEC-2025-255
Jun 13, 2025
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
A credential leak in OpenC3 COSMOS before v6.0.2 allows attackers to access service credentials as environment variables stored in all containers. Affected versions
0.1.0
5.10.0
5.10.1
5.11.0
5.11.1
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
+ 13 more Show less
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.20.0
5.9.2b0
6.0.0
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-28380
PYSEC-2025-254
Jun 13, 2025
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
A cross-site scripting (XSS) vulnerability in OpenC3 COSMOS before v6.0.2 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the URL parameter. Affected versions
0.1.0
5.10.0
5.10.1
5.11.0
5.11.1
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
+ 13 more Show less
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.20.0
5.9.2b0
6.0.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2024-43795
PYSEC-2024-100
GHSA-vfj8-5pj7-2f9g
Oct 02, 2024
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. The login functionality contains a reflected cross-site scripting (XSS) vulnerability. This vulnerability is fixed in 5.19.0. Note: This CVE only affects Open Source Edition, and not OpenC3 COSMOS Enterprise Edition. Affected versions
0.1.0
5.10.0
5.10.1
5.11.0
5.11.1
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
+ 10 more Show less
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.9.2b0
Fixed in
5.19.0
References Updated Oct 08, 2024 · Source: OSV.dev
CVE-2024-46977
PYSEC-2024-101
GHSA-8jxr-mccc-mwg8
Oct 02, 2024
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. A path traversal vulnerability inside of LocalMode's open_local_file method allows an authenticated user with adequate permissions to download any .txt via the ScreensController#show on the web server COSMOS is running on (depending on the file permissions). This vulnerability is fixed in 5.19.0. Affected versions
0.1.0
5.10.0
5.10.1
5.11.0
5.11.1
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
+ 10 more Show less
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.9.2b0
Fixed in
5.19.0
References Updated Oct 08, 2024 · Source: OSV.dev
CVE-2024-47529
PYSEC-2024-121
GHSA-4xqv-47rm-37mm
Oct 02, 2024
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
High
None
None
OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. OpenC3 COSMOS stores the password of a user unencrypted in the LocalStorage of a web browser. This makes the user password susceptible to exfiltration via Cross-site scripting (see GHSL-2024-128). This vulnerability is fixed in 5.19.0. This only affects Open Source edition, and not OpenC3 COSMOS Enterprise Edition. Affected versions
0.1.0
5.10.0
5.10.1
5.11.0
5.11.1
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
+ 10 more Show less
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.9.2b0
Fixed in
5.19.0
References Updated Nov 13, 2024 · Source: OSV.dev | ||
5.16.1
patch
14 CVEs
CVE-2026-42088
PYSEC-2026-2245
GHSA-2wvh-87g2-89hr
May 04, 2026
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. Prior to version 7.0.0-rc3, the Script Runner widget allows users to execute Python and Ruby scripts directly from the openc3-COSMOS-script-runner-api container. Because all the docker containers share a network, users can execute specially crafted scripts to bypass the API permissions check and perform administrative actions, including reading and modifying data inside the Redis database, which can be used to read secrets and change COSMOS settings, as well as read and write to the buckets service, which holds configuration, log, and plugin files. These actions are normally only available from the Admin Console or with administrative privileges. Any user with permission to create and run scripts can connect to any service in the docker network. This issue has been patched in version 7.0.0-rc3. Affected versions
0.1.0
5.10.0
5.10.1
5.11.0
5.11.1
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
+ 40 more Show less
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.20.0
5.9.2b0
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.10.5
6.10.6
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
7.0.0rc2
7.0.0rc3
Fixed in
7.0.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-42086
PYSEC-2026-105
GHSA-ffq5-qpvf-xq7x
May 04, 2026
4.6
/ 10
Medium
Network
Low
Low
Required
Unchanged
Low
Low
None
OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. Prior to version 7.0.0, the Command Sender UI uses an unsafe eval() function on array-like command parameters, which allows a user-supplied payload to execute in the browser when sending a command. This creates a self-XSS risk because an attacker can trigger their own script execution in the victim’s session, if allowed to influence the array parameter input, for example via phishing. If successful, an attacker may read or modify data in the authenticated browser context, including session tokens in local storage. This issue has been patched in version 7.0.0. Affected versions
0.1.0
5.10.0
5.10.1
5.11.0
5.11.1
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
+ 40 more Show less
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.20.0
5.9.2b0
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.10.5
6.10.6
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
7.0.0rc2
7.0.0rc3
Fixed in
7.0.0
Updated May 20, 2026 · Source: OSV.dev
CVE-2026-42085
PYSEC-2026-2243
GHSA-4jvx-93h3-f45h
May 04, 2026
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
None
OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. Prior to versions 6.10.5 and 7.0.0-rc3, OpenC3 COSMOS contains a design flaw in the save_tool_config() function that allows saving tool configuration files at arbitrary locations inside the shared /plugins directory tree by supplying crafted configuration filenames. Although the implementation sufficiently mitigates standard path traversal attacks, by canonicalizing filename to an absolute path, all plugins share this same root directory. That enables users to create arbitrary file structures and overwrite existing configuration files within the shared /plugins directory. This issue has been patched in versions 6.10.5 and 7.0.0-rc3. Affected versions
0.1.0
5.10.0
5.10.1
5.11.0
5.11.1
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
+ 36 more Show less
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.20.0
5.9.2b0
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
Fixed in
6.10.5
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-42084
PYSEC-2026-2242
GHSA-wgx6-g857-jjf7
May 04, 2026
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. Prior to versions 6.10.5 and 7.0.0-rc3, the OpenC3 password change functionality allows a user to change their password without providing the old password, by accepting a valid session token instead. In assumed breach scenarios, this behaviour can be exploited by an attacker who has already obtained a valid session token, to gain persistence in hijacked account (including admin) and prevent legitimate users from accessing the account. This issue has been patched in versions 6.10.5 and 7.0.0-rc3. Affected versions
0.1.0
5.10.0
5.10.1
5.11.0
5.11.1
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
+ 36 more Show less
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.20.0
5.9.2b0
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
Fixed in
6.10.5
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-28389
PYSEC-2025-150
Jun 13, 2025
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Weak password requirements in OpenC3 COSMOS v6.0.0 allow attackers to bypass authentication via a brute force attack. Affected versions
0.1.0
5.10.0
5.10.1
5.11.0
5.11.1
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
+ 13 more Show less
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.20.0
5.9.2b0
6.0.0
References Updated May 21, 2026 · Source: OSV.dev
CVE-2025-28388
PYSEC-2025-258
Jun 13, 2025
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
OpenC3 COSMOS before v6.0.2 was discovered to contain hardcoded credentials for the Service Account. Affected versions
0.1.0
5.10.0
5.10.1
5.11.0
5.11.1
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
+ 13 more Show less
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.20.0
5.9.2b0
6.0.0
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-28386
PYSEC-2025-149
Jun 13, 2025
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
A remote code execution (RCE) vulnerability in the Plugin Management component of OpenC3 COSMOS v6.0.0 allows attackers to execute arbitrary code via uploading a crafted .txt file. Affected versions
0.1.0
5.10.0
5.10.1
5.11.0
5.11.1
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
+ 13 more Show less
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.20.0
5.9.2b0
6.0.0
References Updated May 21, 2026 · Source: OSV.dev
CVE-2025-28384
PYSEC-2025-257
GHSA-p67j-387g-75wc
Jun 13, 2025
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
None
An issue in the /script-api/scripts/ endpoint of OpenC3 COSMOS before 6.1.0 allows attackers to execute a directory traversal. Affected versions
0.1.0
5.10.0
5.10.1
5.11.0
5.11.1
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
+ 13 more Show less
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.20.0
5.9.2b0
6.0.0
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-28382
PYSEC-2025-256
GHSA-cf8v-5mrc-jv7f
Jun 13, 2025
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
An issue in the openc3-api/tables endpoint of OpenC3 COSMOS before 6.1.0 allows attackers to execute a directory traversal. Affected versions
0.1.0
5.10.0
5.10.1
5.11.0
5.11.1
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
+ 13 more Show less
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.20.0
5.9.2b0
6.0.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-28381
PYSEC-2025-255
Jun 13, 2025
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
A credential leak in OpenC3 COSMOS before v6.0.2 allows attackers to access service credentials as environment variables stored in all containers. Affected versions
0.1.0
5.10.0
5.10.1
5.11.0
5.11.1
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
+ 13 more Show less
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.20.0
5.9.2b0
6.0.0
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-28380
PYSEC-2025-254
Jun 13, 2025
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
A cross-site scripting (XSS) vulnerability in OpenC3 COSMOS before v6.0.2 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the URL parameter. Affected versions
0.1.0
5.10.0
5.10.1
5.11.0
5.11.1
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
+ 13 more Show less
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.20.0
5.9.2b0
6.0.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2024-43795
PYSEC-2024-100
GHSA-vfj8-5pj7-2f9g
Oct 02, 2024
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. The login functionality contains a reflected cross-site scripting (XSS) vulnerability. This vulnerability is fixed in 5.19.0. Note: This CVE only affects Open Source Edition, and not OpenC3 COSMOS Enterprise Edition. Affected versions
0.1.0
5.10.0
5.10.1
5.11.0
5.11.1
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
+ 10 more Show less
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.9.2b0
Fixed in
5.19.0
References Updated Oct 08, 2024 · Source: OSV.dev
CVE-2024-46977
PYSEC-2024-101
GHSA-8jxr-mccc-mwg8
Oct 02, 2024
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. A path traversal vulnerability inside of LocalMode's open_local_file method allows an authenticated user with adequate permissions to download any .txt via the ScreensController#show on the web server COSMOS is running on (depending on the file permissions). This vulnerability is fixed in 5.19.0. Affected versions
0.1.0
5.10.0
5.10.1
5.11.0
5.11.1
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
+ 10 more Show less
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.9.2b0
Fixed in
5.19.0
References Updated Oct 08, 2024 · Source: OSV.dev
CVE-2024-47529
PYSEC-2024-121
GHSA-4xqv-47rm-37mm
Oct 02, 2024
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
High
None
None
OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. OpenC3 COSMOS stores the password of a user unencrypted in the LocalStorage of a web browser. This makes the user password susceptible to exfiltration via Cross-site scripting (see GHSL-2024-128). This vulnerability is fixed in 5.19.0. This only affects Open Source edition, and not OpenC3 COSMOS Enterprise Edition. Affected versions
0.1.0
5.10.0
5.10.1
5.11.0
5.11.1
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
+ 10 more Show less
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.9.2b0
Fixed in
5.19.0
References Updated Nov 13, 2024 · Source: OSV.dev | ||
5.16.0
minor
14 CVEs
CVE-2026-42088
PYSEC-2026-2245
GHSA-2wvh-87g2-89hr
May 04, 2026
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. Prior to version 7.0.0-rc3, the Script Runner widget allows users to execute Python and Ruby scripts directly from the openc3-COSMOS-script-runner-api container. Because all the docker containers share a network, users can execute specially crafted scripts to bypass the API permissions check and perform administrative actions, including reading and modifying data inside the Redis database, which can be used to read secrets and change COSMOS settings, as well as read and write to the buckets service, which holds configuration, log, and plugin files. These actions are normally only available from the Admin Console or with administrative privileges. Any user with permission to create and run scripts can connect to any service in the docker network. This issue has been patched in version 7.0.0-rc3. Affected versions
0.1.0
5.10.0
5.10.1
5.11.0
5.11.1
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
+ 40 more Show less
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.20.0
5.9.2b0
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.10.5
6.10.6
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
7.0.0rc2
7.0.0rc3
Fixed in
7.0.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-42086
PYSEC-2026-105
GHSA-ffq5-qpvf-xq7x
May 04, 2026
4.6
/ 10
Medium
Network
Low
Low
Required
Unchanged
Low
Low
None
OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. Prior to version 7.0.0, the Command Sender UI uses an unsafe eval() function on array-like command parameters, which allows a user-supplied payload to execute in the browser when sending a command. This creates a self-XSS risk because an attacker can trigger their own script execution in the victim’s session, if allowed to influence the array parameter input, for example via phishing. If successful, an attacker may read or modify data in the authenticated browser context, including session tokens in local storage. This issue has been patched in version 7.0.0. Affected versions
0.1.0
5.10.0
5.10.1
5.11.0
5.11.1
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
+ 40 more Show less
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.20.0
5.9.2b0
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.10.5
6.10.6
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
7.0.0rc2
7.0.0rc3
Fixed in
7.0.0
Updated May 20, 2026 · Source: OSV.dev
CVE-2026-42085
PYSEC-2026-2243
GHSA-4jvx-93h3-f45h
May 04, 2026
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
None
OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. Prior to versions 6.10.5 and 7.0.0-rc3, OpenC3 COSMOS contains a design flaw in the save_tool_config() function that allows saving tool configuration files at arbitrary locations inside the shared /plugins directory tree by supplying crafted configuration filenames. Although the implementation sufficiently mitigates standard path traversal attacks, by canonicalizing filename to an absolute path, all plugins share this same root directory. That enables users to create arbitrary file structures and overwrite existing configuration files within the shared /plugins directory. This issue has been patched in versions 6.10.5 and 7.0.0-rc3. Affected versions
0.1.0
5.10.0
5.10.1
5.11.0
5.11.1
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
+ 36 more Show less
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.20.0
5.9.2b0
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
Fixed in
6.10.5
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-42084
PYSEC-2026-2242
GHSA-wgx6-g857-jjf7
May 04, 2026
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. Prior to versions 6.10.5 and 7.0.0-rc3, the OpenC3 password change functionality allows a user to change their password without providing the old password, by accepting a valid session token instead. In assumed breach scenarios, this behaviour can be exploited by an attacker who has already obtained a valid session token, to gain persistence in hijacked account (including admin) and prevent legitimate users from accessing the account. This issue has been patched in versions 6.10.5 and 7.0.0-rc3. Affected versions
0.1.0
5.10.0
5.10.1
5.11.0
5.11.1
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
+ 36 more Show less
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.20.0
5.9.2b0
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
Fixed in
6.10.5
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-28389
PYSEC-2025-150
Jun 13, 2025
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Weak password requirements in OpenC3 COSMOS v6.0.0 allow attackers to bypass authentication via a brute force attack. Affected versions
0.1.0
5.10.0
5.10.1
5.11.0
5.11.1
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
+ 13 more Show less
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.20.0
5.9.2b0
6.0.0
References Updated May 21, 2026 · Source: OSV.dev
CVE-2025-28388
PYSEC-2025-258
Jun 13, 2025
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
OpenC3 COSMOS before v6.0.2 was discovered to contain hardcoded credentials for the Service Account. Affected versions
0.1.0
5.10.0
5.10.1
5.11.0
5.11.1
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
+ 13 more Show less
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.20.0
5.9.2b0
6.0.0
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-28386
PYSEC-2025-149
Jun 13, 2025
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
A remote code execution (RCE) vulnerability in the Plugin Management component of OpenC3 COSMOS v6.0.0 allows attackers to execute arbitrary code via uploading a crafted .txt file. Affected versions
0.1.0
5.10.0
5.10.1
5.11.0
5.11.1
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
+ 13 more Show less
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.20.0
5.9.2b0
6.0.0
References Updated May 21, 2026 · Source: OSV.dev
CVE-2025-28384
PYSEC-2025-257
GHSA-p67j-387g-75wc
Jun 13, 2025
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
None
An issue in the /script-api/scripts/ endpoint of OpenC3 COSMOS before 6.1.0 allows attackers to execute a directory traversal. Affected versions
0.1.0
5.10.0
5.10.1
5.11.0
5.11.1
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
+ 13 more Show less
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.20.0
5.9.2b0
6.0.0
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-28382
PYSEC-2025-256
GHSA-cf8v-5mrc-jv7f
Jun 13, 2025
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
An issue in the openc3-api/tables endpoint of OpenC3 COSMOS before 6.1.0 allows attackers to execute a directory traversal. Affected versions
0.1.0
5.10.0
5.10.1
5.11.0
5.11.1
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
+ 13 more Show less
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.20.0
5.9.2b0
6.0.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-28381
PYSEC-2025-255
Jun 13, 2025
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
A credential leak in OpenC3 COSMOS before v6.0.2 allows attackers to access service credentials as environment variables stored in all containers. Affected versions
0.1.0
5.10.0
5.10.1
5.11.0
5.11.1
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
+ 13 more Show less
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.20.0
5.9.2b0
6.0.0
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-28380
PYSEC-2025-254
Jun 13, 2025
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
A cross-site scripting (XSS) vulnerability in OpenC3 COSMOS before v6.0.2 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the URL parameter. Affected versions
0.1.0
5.10.0
5.10.1
5.11.0
5.11.1
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
+ 13 more Show less
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.20.0
5.9.2b0
6.0.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2024-43795
PYSEC-2024-100
GHSA-vfj8-5pj7-2f9g
Oct 02, 2024
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. The login functionality contains a reflected cross-site scripting (XSS) vulnerability. This vulnerability is fixed in 5.19.0. Note: This CVE only affects Open Source Edition, and not OpenC3 COSMOS Enterprise Edition. Affected versions
0.1.0
5.10.0
5.10.1
5.11.0
5.11.1
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
+ 10 more Show less
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.9.2b0
Fixed in
5.19.0
References Updated Oct 08, 2024 · Source: OSV.dev
CVE-2024-46977
PYSEC-2024-101
GHSA-8jxr-mccc-mwg8
Oct 02, 2024
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. A path traversal vulnerability inside of LocalMode's open_local_file method allows an authenticated user with adequate permissions to download any .txt via the ScreensController#show on the web server COSMOS is running on (depending on the file permissions). This vulnerability is fixed in 5.19.0. Affected versions
0.1.0
5.10.0
5.10.1
5.11.0
5.11.1
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
+ 10 more Show less
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.9.2b0
Fixed in
5.19.0
References Updated Oct 08, 2024 · Source: OSV.dev
CVE-2024-47529
PYSEC-2024-121
GHSA-4xqv-47rm-37mm
Oct 02, 2024
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
High
None
None
OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. OpenC3 COSMOS stores the password of a user unencrypted in the LocalStorage of a web browser. This makes the user password susceptible to exfiltration via Cross-site scripting (see GHSL-2024-128). This vulnerability is fixed in 5.19.0. This only affects Open Source edition, and not OpenC3 COSMOS Enterprise Edition. Affected versions
0.1.0
5.10.0
5.10.1
5.11.0
5.11.1
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
+ 10 more Show less
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.9.2b0
Fixed in
5.19.0
References Updated Nov 13, 2024 · Source: OSV.dev | ||
5.15.2
patch
14 CVEs
CVE-2026-42088
PYSEC-2026-2245
GHSA-2wvh-87g2-89hr
May 04, 2026
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. Prior to version 7.0.0-rc3, the Script Runner widget allows users to execute Python and Ruby scripts directly from the openc3-COSMOS-script-runner-api container. Because all the docker containers share a network, users can execute specially crafted scripts to bypass the API permissions check and perform administrative actions, including reading and modifying data inside the Redis database, which can be used to read secrets and change COSMOS settings, as well as read and write to the buckets service, which holds configuration, log, and plugin files. These actions are normally only available from the Admin Console or with administrative privileges. Any user with permission to create and run scripts can connect to any service in the docker network. This issue has been patched in version 7.0.0-rc3. Affected versions
0.1.0
5.10.0
5.10.1
5.11.0
5.11.1
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
+ 40 more Show less
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.20.0
5.9.2b0
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.10.5
6.10.6
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
7.0.0rc2
7.0.0rc3
Fixed in
7.0.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-42086
PYSEC-2026-105
GHSA-ffq5-qpvf-xq7x
May 04, 2026
4.6
/ 10
Medium
Network
Low
Low
Required
Unchanged
Low
Low
None
OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. Prior to version 7.0.0, the Command Sender UI uses an unsafe eval() function on array-like command parameters, which allows a user-supplied payload to execute in the browser when sending a command. This creates a self-XSS risk because an attacker can trigger their own script execution in the victim’s session, if allowed to influence the array parameter input, for example via phishing. If successful, an attacker may read or modify data in the authenticated browser context, including session tokens in local storage. This issue has been patched in version 7.0.0. Affected versions
0.1.0
5.10.0
5.10.1
5.11.0
5.11.1
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
+ 40 more Show less
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.20.0
5.9.2b0
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.10.5
6.10.6
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
7.0.0rc2
7.0.0rc3
Fixed in
7.0.0
Updated May 20, 2026 · Source: OSV.dev
CVE-2026-42085
PYSEC-2026-2243
GHSA-4jvx-93h3-f45h
May 04, 2026
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
None
OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. Prior to versions 6.10.5 and 7.0.0-rc3, OpenC3 COSMOS contains a design flaw in the save_tool_config() function that allows saving tool configuration files at arbitrary locations inside the shared /plugins directory tree by supplying crafted configuration filenames. Although the implementation sufficiently mitigates standard path traversal attacks, by canonicalizing filename to an absolute path, all plugins share this same root directory. That enables users to create arbitrary file structures and overwrite existing configuration files within the shared /plugins directory. This issue has been patched in versions 6.10.5 and 7.0.0-rc3. Affected versions
0.1.0
5.10.0
5.10.1
5.11.0
5.11.1
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
+ 36 more Show less
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.20.0
5.9.2b0
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
Fixed in
6.10.5
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-42084
PYSEC-2026-2242
GHSA-wgx6-g857-jjf7
May 04, 2026
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. Prior to versions 6.10.5 and 7.0.0-rc3, the OpenC3 password change functionality allows a user to change their password without providing the old password, by accepting a valid session token instead. In assumed breach scenarios, this behaviour can be exploited by an attacker who has already obtained a valid session token, to gain persistence in hijacked account (including admin) and prevent legitimate users from accessing the account. This issue has been patched in versions 6.10.5 and 7.0.0-rc3. Affected versions
0.1.0
5.10.0
5.10.1
5.11.0
5.11.1
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
+ 36 more Show less
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.20.0
5.9.2b0
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
Fixed in
6.10.5
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-28389
PYSEC-2025-150
Jun 13, 2025
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Weak password requirements in OpenC3 COSMOS v6.0.0 allow attackers to bypass authentication via a brute force attack. Affected versions
0.1.0
5.10.0
5.10.1
5.11.0
5.11.1
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
+ 13 more Show less
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.20.0
5.9.2b0
6.0.0
References Updated May 21, 2026 · Source: OSV.dev
CVE-2025-28388
PYSEC-2025-258
Jun 13, 2025
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
OpenC3 COSMOS before v6.0.2 was discovered to contain hardcoded credentials for the Service Account. Affected versions
0.1.0
5.10.0
5.10.1
5.11.0
5.11.1
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
+ 13 more Show less
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.20.0
5.9.2b0
6.0.0
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-28386
PYSEC-2025-149
Jun 13, 2025
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
A remote code execution (RCE) vulnerability in the Plugin Management component of OpenC3 COSMOS v6.0.0 allows attackers to execute arbitrary code via uploading a crafted .txt file. Affected versions
0.1.0
5.10.0
5.10.1
5.11.0
5.11.1
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
+ 13 more Show less
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.20.0
5.9.2b0
6.0.0
References Updated May 21, 2026 · Source: OSV.dev
CVE-2025-28384
PYSEC-2025-257
GHSA-p67j-387g-75wc
Jun 13, 2025
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
None
An issue in the /script-api/scripts/ endpoint of OpenC3 COSMOS before 6.1.0 allows attackers to execute a directory traversal. Affected versions
0.1.0
5.10.0
5.10.1
5.11.0
5.11.1
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
+ 13 more Show less
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.20.0
5.9.2b0
6.0.0
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-28382
PYSEC-2025-256
GHSA-cf8v-5mrc-jv7f
Jun 13, 2025
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
An issue in the openc3-api/tables endpoint of OpenC3 COSMOS before 6.1.0 allows attackers to execute a directory traversal. Affected versions
0.1.0
5.10.0
5.10.1
5.11.0
5.11.1
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
+ 13 more Show less
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.20.0
5.9.2b0
6.0.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-28381
PYSEC-2025-255
Jun 13, 2025
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
A credential leak in OpenC3 COSMOS before v6.0.2 allows attackers to access service credentials as environment variables stored in all containers. Affected versions
0.1.0
5.10.0
5.10.1
5.11.0
5.11.1
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
+ 13 more Show less
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.20.0
5.9.2b0
6.0.0
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-28380
PYSEC-2025-254
Jun 13, 2025
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
A cross-site scripting (XSS) vulnerability in OpenC3 COSMOS before v6.0.2 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the URL parameter. Affected versions
0.1.0
5.10.0
5.10.1
5.11.0
5.11.1
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
+ 13 more Show less
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.20.0
5.9.2b0
6.0.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2024-43795
PYSEC-2024-100
GHSA-vfj8-5pj7-2f9g
Oct 02, 2024
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. The login functionality contains a reflected cross-site scripting (XSS) vulnerability. This vulnerability is fixed in 5.19.0. Note: This CVE only affects Open Source Edition, and not OpenC3 COSMOS Enterprise Edition. Affected versions
0.1.0
5.10.0
5.10.1
5.11.0
5.11.1
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
+ 10 more Show less
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.9.2b0
Fixed in
5.19.0
References Updated Oct 08, 2024 · Source: OSV.dev
CVE-2024-46977
PYSEC-2024-101
GHSA-8jxr-mccc-mwg8
Oct 02, 2024
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. A path traversal vulnerability inside of LocalMode's open_local_file method allows an authenticated user with adequate permissions to download any .txt via the ScreensController#show on the web server COSMOS is running on (depending on the file permissions). This vulnerability is fixed in 5.19.0. Affected versions
0.1.0
5.10.0
5.10.1
5.11.0
5.11.1
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
+ 10 more Show less
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.9.2b0
Fixed in
5.19.0
References Updated Oct 08, 2024 · Source: OSV.dev
CVE-2024-47529
PYSEC-2024-121
GHSA-4xqv-47rm-37mm
Oct 02, 2024
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
High
None
None
OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. OpenC3 COSMOS stores the password of a user unencrypted in the LocalStorage of a web browser. This makes the user password susceptible to exfiltration via Cross-site scripting (see GHSL-2024-128). This vulnerability is fixed in 5.19.0. This only affects Open Source edition, and not OpenC3 COSMOS Enterprise Edition. Affected versions
0.1.0
5.10.0
5.10.1
5.11.0
5.11.1
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
+ 10 more Show less
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.9.2b0
Fixed in
5.19.0
References Updated Nov 13, 2024 · Source: OSV.dev | ||
5.15.1
patch
14 CVEs
CVE-2026-42088
PYSEC-2026-2245
GHSA-2wvh-87g2-89hr
May 04, 2026
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. Prior to version 7.0.0-rc3, the Script Runner widget allows users to execute Python and Ruby scripts directly from the openc3-COSMOS-script-runner-api container. Because all the docker containers share a network, users can execute specially crafted scripts to bypass the API permissions check and perform administrative actions, including reading and modifying data inside the Redis database, which can be used to read secrets and change COSMOS settings, as well as read and write to the buckets service, which holds configuration, log, and plugin files. These actions are normally only available from the Admin Console or with administrative privileges. Any user with permission to create and run scripts can connect to any service in the docker network. This issue has been patched in version 7.0.0-rc3. Affected versions
0.1.0
5.10.0
5.10.1
5.11.0
5.11.1
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
+ 40 more Show less
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.20.0
5.9.2b0
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.10.5
6.10.6
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
7.0.0rc2
7.0.0rc3
Fixed in
7.0.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-42086
PYSEC-2026-105
GHSA-ffq5-qpvf-xq7x
May 04, 2026
4.6
/ 10
Medium
Network
Low
Low
Required
Unchanged
Low
Low
None
OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. Prior to version 7.0.0, the Command Sender UI uses an unsafe eval() function on array-like command parameters, which allows a user-supplied payload to execute in the browser when sending a command. This creates a self-XSS risk because an attacker can trigger their own script execution in the victim’s session, if allowed to influence the array parameter input, for example via phishing. If successful, an attacker may read or modify data in the authenticated browser context, including session tokens in local storage. This issue has been patched in version 7.0.0. Affected versions
0.1.0
5.10.0
5.10.1
5.11.0
5.11.1
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
+ 40 more Show less
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.20.0
5.9.2b0
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.10.5
6.10.6
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
7.0.0rc2
7.0.0rc3
Fixed in
7.0.0
Updated May 20, 2026 · Source: OSV.dev
CVE-2026-42085
PYSEC-2026-2243
GHSA-4jvx-93h3-f45h
May 04, 2026
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
None
OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. Prior to versions 6.10.5 and 7.0.0-rc3, OpenC3 COSMOS contains a design flaw in the save_tool_config() function that allows saving tool configuration files at arbitrary locations inside the shared /plugins directory tree by supplying crafted configuration filenames. Although the implementation sufficiently mitigates standard path traversal attacks, by canonicalizing filename to an absolute path, all plugins share this same root directory. That enables users to create arbitrary file structures and overwrite existing configuration files within the shared /plugins directory. This issue has been patched in versions 6.10.5 and 7.0.0-rc3. Affected versions
0.1.0
5.10.0
5.10.1
5.11.0
5.11.1
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
+ 36 more Show less
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.20.0
5.9.2b0
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
Fixed in
6.10.5
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-42084
PYSEC-2026-2242
GHSA-wgx6-g857-jjf7
May 04, 2026
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. Prior to versions 6.10.5 and 7.0.0-rc3, the OpenC3 password change functionality allows a user to change their password without providing the old password, by accepting a valid session token instead. In assumed breach scenarios, this behaviour can be exploited by an attacker who has already obtained a valid session token, to gain persistence in hijacked account (including admin) and prevent legitimate users from accessing the account. This issue has been patched in versions 6.10.5 and 7.0.0-rc3. Affected versions
0.1.0
5.10.0
5.10.1
5.11.0
5.11.1
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
+ 36 more Show less
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.20.0
5.9.2b0
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
Fixed in
6.10.5
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-28389
PYSEC-2025-150
Jun 13, 2025
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Weak password requirements in OpenC3 COSMOS v6.0.0 allow attackers to bypass authentication via a brute force attack. Affected versions
0.1.0
5.10.0
5.10.1
5.11.0
5.11.1
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
+ 13 more Show less
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.20.0
5.9.2b0
6.0.0
References Updated May 21, 2026 · Source: OSV.dev
CVE-2025-28388
PYSEC-2025-258
Jun 13, 2025
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
OpenC3 COSMOS before v6.0.2 was discovered to contain hardcoded credentials for the Service Account. Affected versions
0.1.0
5.10.0
5.10.1
5.11.0
5.11.1
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
+ 13 more Show less
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.20.0
5.9.2b0
6.0.0
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-28386
PYSEC-2025-149
Jun 13, 2025
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
A remote code execution (RCE) vulnerability in the Plugin Management component of OpenC3 COSMOS v6.0.0 allows attackers to execute arbitrary code via uploading a crafted .txt file. Affected versions
0.1.0
5.10.0
5.10.1
5.11.0
5.11.1
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
+ 13 more Show less
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.20.0
5.9.2b0
6.0.0
References Updated May 21, 2026 · Source: OSV.dev
CVE-2025-28384
PYSEC-2025-257
GHSA-p67j-387g-75wc
Jun 13, 2025
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
None
An issue in the /script-api/scripts/ endpoint of OpenC3 COSMOS before 6.1.0 allows attackers to execute a directory traversal. Affected versions
0.1.0
5.10.0
5.10.1
5.11.0
5.11.1
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
+ 13 more Show less
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.20.0
5.9.2b0
6.0.0
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-28382
PYSEC-2025-256
GHSA-cf8v-5mrc-jv7f
Jun 13, 2025
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
An issue in the openc3-api/tables endpoint of OpenC3 COSMOS before 6.1.0 allows attackers to execute a directory traversal. Affected versions
0.1.0
5.10.0
5.10.1
5.11.0
5.11.1
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
+ 13 more Show less
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.20.0
5.9.2b0
6.0.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-28381
PYSEC-2025-255
Jun 13, 2025
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
A credential leak in OpenC3 COSMOS before v6.0.2 allows attackers to access service credentials as environment variables stored in all containers. Affected versions
0.1.0
5.10.0
5.10.1
5.11.0
5.11.1
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
+ 13 more Show less
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.20.0
5.9.2b0
6.0.0
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-28380
PYSEC-2025-254
Jun 13, 2025
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
A cross-site scripting (XSS) vulnerability in OpenC3 COSMOS before v6.0.2 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the URL parameter. Affected versions
0.1.0
5.10.0
5.10.1
5.11.0
5.11.1
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
+ 13 more Show less
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.20.0
5.9.2b0
6.0.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2024-43795
PYSEC-2024-100
GHSA-vfj8-5pj7-2f9g
Oct 02, 2024
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. The login functionality contains a reflected cross-site scripting (XSS) vulnerability. This vulnerability is fixed in 5.19.0. Note: This CVE only affects Open Source Edition, and not OpenC3 COSMOS Enterprise Edition. Affected versions
0.1.0
5.10.0
5.10.1
5.11.0
5.11.1
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
+ 10 more Show less
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.9.2b0
Fixed in
5.19.0
References Updated Oct 08, 2024 · Source: OSV.dev
CVE-2024-46977
PYSEC-2024-101
GHSA-8jxr-mccc-mwg8
Oct 02, 2024
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. A path traversal vulnerability inside of LocalMode's open_local_file method allows an authenticated user with adequate permissions to download any .txt via the ScreensController#show on the web server COSMOS is running on (depending on the file permissions). This vulnerability is fixed in 5.19.0. Affected versions
0.1.0
5.10.0
5.10.1
5.11.0
5.11.1
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
+ 10 more Show less
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.9.2b0
Fixed in
5.19.0
References Updated Oct 08, 2024 · Source: OSV.dev
CVE-2024-47529
PYSEC-2024-121
GHSA-4xqv-47rm-37mm
Oct 02, 2024
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
High
None
None
OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. OpenC3 COSMOS stores the password of a user unencrypted in the LocalStorage of a web browser. This makes the user password susceptible to exfiltration via Cross-site scripting (see GHSL-2024-128). This vulnerability is fixed in 5.19.0. This only affects Open Source edition, and not OpenC3 COSMOS Enterprise Edition. Affected versions
0.1.0
5.10.0
5.10.1
5.11.0
5.11.1
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
+ 10 more Show less
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.9.2b0
Fixed in
5.19.0
References Updated Nov 13, 2024 · Source: OSV.dev | ||
5.15.0
minor
14 CVEs
CVE-2026-42088
PYSEC-2026-2245
GHSA-2wvh-87g2-89hr
May 04, 2026
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. Prior to version 7.0.0-rc3, the Script Runner widget allows users to execute Python and Ruby scripts directly from the openc3-COSMOS-script-runner-api container. Because all the docker containers share a network, users can execute specially crafted scripts to bypass the API permissions check and perform administrative actions, including reading and modifying data inside the Redis database, which can be used to read secrets and change COSMOS settings, as well as read and write to the buckets service, which holds configuration, log, and plugin files. These actions are normally only available from the Admin Console or with administrative privileges. Any user with permission to create and run scripts can connect to any service in the docker network. This issue has been patched in version 7.0.0-rc3. Affected versions
0.1.0
5.10.0
5.10.1
5.11.0
5.11.1
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
+ 40 more Show less
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.20.0
5.9.2b0
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.10.5
6.10.6
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
7.0.0rc2
7.0.0rc3
Fixed in
7.0.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-42086
PYSEC-2026-105
GHSA-ffq5-qpvf-xq7x
May 04, 2026
4.6
/ 10
Medium
Network
Low
Low
Required
Unchanged
Low
Low
None
OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. Prior to version 7.0.0, the Command Sender UI uses an unsafe eval() function on array-like command parameters, which allows a user-supplied payload to execute in the browser when sending a command. This creates a self-XSS risk because an attacker can trigger their own script execution in the victim’s session, if allowed to influence the array parameter input, for example via phishing. If successful, an attacker may read or modify data in the authenticated browser context, including session tokens in local storage. This issue has been patched in version 7.0.0. Affected versions
0.1.0
5.10.0
5.10.1
5.11.0
5.11.1
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
+ 40 more Show less
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.20.0
5.9.2b0
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.10.5
6.10.6
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
7.0.0rc2
7.0.0rc3
Fixed in
7.0.0
Updated May 20, 2026 · Source: OSV.dev
CVE-2026-42085
PYSEC-2026-2243
GHSA-4jvx-93h3-f45h
May 04, 2026
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
None
OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. Prior to versions 6.10.5 and 7.0.0-rc3, OpenC3 COSMOS contains a design flaw in the save_tool_config() function that allows saving tool configuration files at arbitrary locations inside the shared /plugins directory tree by supplying crafted configuration filenames. Although the implementation sufficiently mitigates standard path traversal attacks, by canonicalizing filename to an absolute path, all plugins share this same root directory. That enables users to create arbitrary file structures and overwrite existing configuration files within the shared /plugins directory. This issue has been patched in versions 6.10.5 and 7.0.0-rc3. Affected versions
0.1.0
5.10.0
5.10.1
5.11.0
5.11.1
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
+ 36 more Show less
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.20.0
5.9.2b0
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
Fixed in
6.10.5
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-42084
PYSEC-2026-2242
GHSA-wgx6-g857-jjf7
May 04, 2026
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. Prior to versions 6.10.5 and 7.0.0-rc3, the OpenC3 password change functionality allows a user to change their password without providing the old password, by accepting a valid session token instead. In assumed breach scenarios, this behaviour can be exploited by an attacker who has already obtained a valid session token, to gain persistence in hijacked account (including admin) and prevent legitimate users from accessing the account. This issue has been patched in versions 6.10.5 and 7.0.0-rc3. Affected versions
0.1.0
5.10.0
5.10.1
5.11.0
5.11.1
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
+ 36 more Show less
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.20.0
5.9.2b0
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
Fixed in
6.10.5
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-28389
PYSEC-2025-150
Jun 13, 2025
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Weak password requirements in OpenC3 COSMOS v6.0.0 allow attackers to bypass authentication via a brute force attack. Affected versions
0.1.0
5.10.0
5.10.1
5.11.0
5.11.1
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
+ 13 more Show less
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.20.0
5.9.2b0
6.0.0
References Updated May 21, 2026 · Source: OSV.dev
CVE-2025-28388
PYSEC-2025-258
Jun 13, 2025
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
OpenC3 COSMOS before v6.0.2 was discovered to contain hardcoded credentials for the Service Account. Affected versions
0.1.0
5.10.0
5.10.1
5.11.0
5.11.1
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
+ 13 more Show less
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.20.0
5.9.2b0
6.0.0
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-28386
PYSEC-2025-149
Jun 13, 2025
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
A remote code execution (RCE) vulnerability in the Plugin Management component of OpenC3 COSMOS v6.0.0 allows attackers to execute arbitrary code via uploading a crafted .txt file. Affected versions
0.1.0
5.10.0
5.10.1
5.11.0
5.11.1
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
+ 13 more Show less
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.20.0
5.9.2b0
6.0.0
References Updated May 21, 2026 · Source: OSV.dev
CVE-2025-28384
PYSEC-2025-257
GHSA-p67j-387g-75wc
Jun 13, 2025
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
None
An issue in the /script-api/scripts/ endpoint of OpenC3 COSMOS before 6.1.0 allows attackers to execute a directory traversal. Affected versions
0.1.0
5.10.0
5.10.1
5.11.0
5.11.1
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
+ 13 more Show less
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.20.0
5.9.2b0
6.0.0
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-28382
PYSEC-2025-256
GHSA-cf8v-5mrc-jv7f
Jun 13, 2025
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
An issue in the openc3-api/tables endpoint of OpenC3 COSMOS before 6.1.0 allows attackers to execute a directory traversal. Affected versions
0.1.0
5.10.0
5.10.1
5.11.0
5.11.1
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
+ 13 more Show less
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.20.0
5.9.2b0
6.0.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-28381
PYSEC-2025-255
Jun 13, 2025
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
A credential leak in OpenC3 COSMOS before v6.0.2 allows attackers to access service credentials as environment variables stored in all containers. Affected versions
0.1.0
5.10.0
5.10.1
5.11.0
5.11.1
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
+ 13 more Show less
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.20.0
5.9.2b0
6.0.0
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-28380
PYSEC-2025-254
Jun 13, 2025
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
A cross-site scripting (XSS) vulnerability in OpenC3 COSMOS before v6.0.2 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the URL parameter. Affected versions
0.1.0
5.10.0
5.10.1
5.11.0
5.11.1
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
+ 13 more Show less
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.20.0
5.9.2b0
6.0.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2024-43795
PYSEC-2024-100
GHSA-vfj8-5pj7-2f9g
Oct 02, 2024
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. The login functionality contains a reflected cross-site scripting (XSS) vulnerability. This vulnerability is fixed in 5.19.0. Note: This CVE only affects Open Source Edition, and not OpenC3 COSMOS Enterprise Edition. Affected versions
0.1.0
5.10.0
5.10.1
5.11.0
5.11.1
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
+ 10 more Show less
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.9.2b0
Fixed in
5.19.0
References Updated Oct 08, 2024 · Source: OSV.dev
CVE-2024-46977
PYSEC-2024-101
GHSA-8jxr-mccc-mwg8
Oct 02, 2024
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. A path traversal vulnerability inside of LocalMode's open_local_file method allows an authenticated user with adequate permissions to download any .txt via the ScreensController#show on the web server COSMOS is running on (depending on the file permissions). This vulnerability is fixed in 5.19.0. Affected versions
0.1.0
5.10.0
5.10.1
5.11.0
5.11.1
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
+ 10 more Show less
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.9.2b0
Fixed in
5.19.0
References Updated Oct 08, 2024 · Source: OSV.dev
CVE-2024-47529
PYSEC-2024-121
GHSA-4xqv-47rm-37mm
Oct 02, 2024
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
High
None
None
OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. OpenC3 COSMOS stores the password of a user unencrypted in the LocalStorage of a web browser. This makes the user password susceptible to exfiltration via Cross-site scripting (see GHSL-2024-128). This vulnerability is fixed in 5.19.0. This only affects Open Source edition, and not OpenC3 COSMOS Enterprise Edition. Affected versions
0.1.0
5.10.0
5.10.1
5.11.0
5.11.1
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
+ 10 more Show less
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.9.2b0
Fixed in
5.19.0
References Updated Nov 13, 2024 · Source: OSV.dev | ||
5.14.2
patch
14 CVEs
CVE-2026-42088
PYSEC-2026-2245
GHSA-2wvh-87g2-89hr
May 04, 2026
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. Prior to version 7.0.0-rc3, the Script Runner widget allows users to execute Python and Ruby scripts directly from the openc3-COSMOS-script-runner-api container. Because all the docker containers share a network, users can execute specially crafted scripts to bypass the API permissions check and perform administrative actions, including reading and modifying data inside the Redis database, which can be used to read secrets and change COSMOS settings, as well as read and write to the buckets service, which holds configuration, log, and plugin files. These actions are normally only available from the Admin Console or with administrative privileges. Any user with permission to create and run scripts can connect to any service in the docker network. This issue has been patched in version 7.0.0-rc3. Affected versions
0.1.0
5.10.0
5.10.1
5.11.0
5.11.1
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
+ 40 more Show less
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.20.0
5.9.2b0
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.10.5
6.10.6
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
7.0.0rc2
7.0.0rc3
Fixed in
7.0.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-42086
PYSEC-2026-105
GHSA-ffq5-qpvf-xq7x
May 04, 2026
4.6
/ 10
Medium
Network
Low
Low
Required
Unchanged
Low
Low
None
OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. Prior to version 7.0.0, the Command Sender UI uses an unsafe eval() function on array-like command parameters, which allows a user-supplied payload to execute in the browser when sending a command. This creates a self-XSS risk because an attacker can trigger their own script execution in the victim’s session, if allowed to influence the array parameter input, for example via phishing. If successful, an attacker may read or modify data in the authenticated browser context, including session tokens in local storage. This issue has been patched in version 7.0.0. Affected versions
0.1.0
5.10.0
5.10.1
5.11.0
5.11.1
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
+ 40 more Show less
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.20.0
5.9.2b0
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.10.5
6.10.6
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
7.0.0rc2
7.0.0rc3
Fixed in
7.0.0
Updated May 20, 2026 · Source: OSV.dev
CVE-2026-42085
PYSEC-2026-2243
GHSA-4jvx-93h3-f45h
May 04, 2026
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
None
OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. Prior to versions 6.10.5 and 7.0.0-rc3, OpenC3 COSMOS contains a design flaw in the save_tool_config() function that allows saving tool configuration files at arbitrary locations inside the shared /plugins directory tree by supplying crafted configuration filenames. Although the implementation sufficiently mitigates standard path traversal attacks, by canonicalizing filename to an absolute path, all plugins share this same root directory. That enables users to create arbitrary file structures and overwrite existing configuration files within the shared /plugins directory. This issue has been patched in versions 6.10.5 and 7.0.0-rc3. Affected versions
0.1.0
5.10.0
5.10.1
5.11.0
5.11.1
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
+ 36 more Show less
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.20.0
5.9.2b0
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
Fixed in
6.10.5
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-42084
PYSEC-2026-2242
GHSA-wgx6-g857-jjf7
May 04, 2026
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. Prior to versions 6.10.5 and 7.0.0-rc3, the OpenC3 password change functionality allows a user to change their password without providing the old password, by accepting a valid session token instead. In assumed breach scenarios, this behaviour can be exploited by an attacker who has already obtained a valid session token, to gain persistence in hijacked account (including admin) and prevent legitimate users from accessing the account. This issue has been patched in versions 6.10.5 and 7.0.0-rc3. Affected versions
0.1.0
5.10.0
5.10.1
5.11.0
5.11.1
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
+ 36 more Show less
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.20.0
5.9.2b0
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
Fixed in
6.10.5
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-28389
PYSEC-2025-150
Jun 13, 2025
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Weak password requirements in OpenC3 COSMOS v6.0.0 allow attackers to bypass authentication via a brute force attack. Affected versions
0.1.0
5.10.0
5.10.1
5.11.0
5.11.1
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
+ 13 more Show less
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.20.0
5.9.2b0
6.0.0
References Updated May 21, 2026 · Source: OSV.dev
CVE-2025-28388
PYSEC-2025-258
Jun 13, 2025
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
OpenC3 COSMOS before v6.0.2 was discovered to contain hardcoded credentials for the Service Account. Affected versions
0.1.0
5.10.0
5.10.1
5.11.0
5.11.1
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
+ 13 more Show less
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.20.0
5.9.2b0
6.0.0
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-28386
PYSEC-2025-149
Jun 13, 2025
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
A remote code execution (RCE) vulnerability in the Plugin Management component of OpenC3 COSMOS v6.0.0 allows attackers to execute arbitrary code via uploading a crafted .txt file. Affected versions
0.1.0
5.10.0
5.10.1
5.11.0
5.11.1
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
+ 13 more Show less
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.20.0
5.9.2b0
6.0.0
References Updated May 21, 2026 · Source: OSV.dev
CVE-2025-28384
PYSEC-2025-257
GHSA-p67j-387g-75wc
Jun 13, 2025
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
None
An issue in the /script-api/scripts/ endpoint of OpenC3 COSMOS before 6.1.0 allows attackers to execute a directory traversal. Affected versions
0.1.0
5.10.0
5.10.1
5.11.0
5.11.1
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
+ 13 more Show less
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.20.0
5.9.2b0
6.0.0
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-28382
PYSEC-2025-256
GHSA-cf8v-5mrc-jv7f
Jun 13, 2025
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
An issue in the openc3-api/tables endpoint of OpenC3 COSMOS before 6.1.0 allows attackers to execute a directory traversal. Affected versions
0.1.0
5.10.0
5.10.1
5.11.0
5.11.1
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
+ 13 more Show less
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.20.0
5.9.2b0
6.0.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-28381
PYSEC-2025-255
Jun 13, 2025
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
A credential leak in OpenC3 COSMOS before v6.0.2 allows attackers to access service credentials as environment variables stored in all containers. Affected versions
0.1.0
5.10.0
5.10.1
5.11.0
5.11.1
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
+ 13 more Show less
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.20.0
5.9.2b0
6.0.0
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-28380
PYSEC-2025-254
Jun 13, 2025
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
A cross-site scripting (XSS) vulnerability in OpenC3 COSMOS before v6.0.2 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the URL parameter. Affected versions
0.1.0
5.10.0
5.10.1
5.11.0
5.11.1
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
+ 13 more Show less
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.20.0
5.9.2b0
6.0.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2024-43795
PYSEC-2024-100
GHSA-vfj8-5pj7-2f9g
Oct 02, 2024
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. The login functionality contains a reflected cross-site scripting (XSS) vulnerability. This vulnerability is fixed in 5.19.0. Note: This CVE only affects Open Source Edition, and not OpenC3 COSMOS Enterprise Edition. Affected versions
0.1.0
5.10.0
5.10.1
5.11.0
5.11.1
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
+ 10 more Show less
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.9.2b0
Fixed in
5.19.0
References Updated Oct 08, 2024 · Source: OSV.dev
CVE-2024-46977
PYSEC-2024-101
GHSA-8jxr-mccc-mwg8
Oct 02, 2024
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. A path traversal vulnerability inside of LocalMode's open_local_file method allows an authenticated user with adequate permissions to download any .txt via the ScreensController#show on the web server COSMOS is running on (depending on the file permissions). This vulnerability is fixed in 5.19.0. Affected versions
0.1.0
5.10.0
5.10.1
5.11.0
5.11.1
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
+ 10 more Show less
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.9.2b0
Fixed in
5.19.0
References Updated Oct 08, 2024 · Source: OSV.dev
CVE-2024-47529
PYSEC-2024-121
GHSA-4xqv-47rm-37mm
Oct 02, 2024
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
High
None
None
OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. OpenC3 COSMOS stores the password of a user unencrypted in the LocalStorage of a web browser. This makes the user password susceptible to exfiltration via Cross-site scripting (see GHSL-2024-128). This vulnerability is fixed in 5.19.0. This only affects Open Source edition, and not OpenC3 COSMOS Enterprise Edition. Affected versions
0.1.0
5.10.0
5.10.1
5.11.0
5.11.1
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
+ 10 more Show less
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.9.2b0
Fixed in
5.19.0
References Updated Nov 13, 2024 · Source: OSV.dev | ||
5.14.1
patch
14 CVEs
CVE-2026-42088
PYSEC-2026-2245
GHSA-2wvh-87g2-89hr
May 04, 2026
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. Prior to version 7.0.0-rc3, the Script Runner widget allows users to execute Python and Ruby scripts directly from the openc3-COSMOS-script-runner-api container. Because all the docker containers share a network, users can execute specially crafted scripts to bypass the API permissions check and perform administrative actions, including reading and modifying data inside the Redis database, which can be used to read secrets and change COSMOS settings, as well as read and write to the buckets service, which holds configuration, log, and plugin files. These actions are normally only available from the Admin Console or with administrative privileges. Any user with permission to create and run scripts can connect to any service in the docker network. This issue has been patched in version 7.0.0-rc3. Affected versions
0.1.0
5.10.0
5.10.1
5.11.0
5.11.1
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
+ 40 more Show less
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.20.0
5.9.2b0
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.10.5
6.10.6
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
7.0.0rc2
7.0.0rc3
Fixed in
7.0.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-42086
PYSEC-2026-105
GHSA-ffq5-qpvf-xq7x
May 04, 2026
4.6
/ 10
Medium
Network
Low
Low
Required
Unchanged
Low
Low
None
OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. Prior to version 7.0.0, the Command Sender UI uses an unsafe eval() function on array-like command parameters, which allows a user-supplied payload to execute in the browser when sending a command. This creates a self-XSS risk because an attacker can trigger their own script execution in the victim’s session, if allowed to influence the array parameter input, for example via phishing. If successful, an attacker may read or modify data in the authenticated browser context, including session tokens in local storage. This issue has been patched in version 7.0.0. Affected versions
0.1.0
5.10.0
5.10.1
5.11.0
5.11.1
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
+ 40 more Show less
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.20.0
5.9.2b0
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.10.5
6.10.6
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
7.0.0rc2
7.0.0rc3
Fixed in
7.0.0
Updated May 20, 2026 · Source: OSV.dev
CVE-2026-42085
PYSEC-2026-2243
GHSA-4jvx-93h3-f45h
May 04, 2026
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
None
OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. Prior to versions 6.10.5 and 7.0.0-rc3, OpenC3 COSMOS contains a design flaw in the save_tool_config() function that allows saving tool configuration files at arbitrary locations inside the shared /plugins directory tree by supplying crafted configuration filenames. Although the implementation sufficiently mitigates standard path traversal attacks, by canonicalizing filename to an absolute path, all plugins share this same root directory. That enables users to create arbitrary file structures and overwrite existing configuration files within the shared /plugins directory. This issue has been patched in versions 6.10.5 and 7.0.0-rc3. Affected versions
0.1.0
5.10.0
5.10.1
5.11.0
5.11.1
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
+ 36 more Show less
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.20.0
5.9.2b0
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
Fixed in
6.10.5
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-42084
PYSEC-2026-2242
GHSA-wgx6-g857-jjf7
May 04, 2026
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. Prior to versions 6.10.5 and 7.0.0-rc3, the OpenC3 password change functionality allows a user to change their password without providing the old password, by accepting a valid session token instead. In assumed breach scenarios, this behaviour can be exploited by an attacker who has already obtained a valid session token, to gain persistence in hijacked account (including admin) and prevent legitimate users from accessing the account. This issue has been patched in versions 6.10.5 and 7.0.0-rc3. Affected versions
0.1.0
5.10.0
5.10.1
5.11.0
5.11.1
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
+ 36 more Show less
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.20.0
5.9.2b0
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
Fixed in
6.10.5
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-28389
PYSEC-2025-150
Jun 13, 2025
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Weak password requirements in OpenC3 COSMOS v6.0.0 allow attackers to bypass authentication via a brute force attack. Affected versions
0.1.0
5.10.0
5.10.1
5.11.0
5.11.1
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
+ 13 more Show less
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.20.0
5.9.2b0
6.0.0
References Updated May 21, 2026 · Source: OSV.dev
CVE-2025-28388
PYSEC-2025-258
Jun 13, 2025
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
OpenC3 COSMOS before v6.0.2 was discovered to contain hardcoded credentials for the Service Account. Affected versions
0.1.0
5.10.0
5.10.1
5.11.0
5.11.1
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
+ 13 more Show less
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.20.0
5.9.2b0
6.0.0
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-28386
PYSEC-2025-149
Jun 13, 2025
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
A remote code execution (RCE) vulnerability in the Plugin Management component of OpenC3 COSMOS v6.0.0 allows attackers to execute arbitrary code via uploading a crafted .txt file. Affected versions
0.1.0
5.10.0
5.10.1
5.11.0
5.11.1
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
+ 13 more Show less
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.20.0
5.9.2b0
6.0.0
References Updated May 21, 2026 · Source: OSV.dev
CVE-2025-28384
PYSEC-2025-257
GHSA-p67j-387g-75wc
Jun 13, 2025
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
None
An issue in the /script-api/scripts/ endpoint of OpenC3 COSMOS before 6.1.0 allows attackers to execute a directory traversal. Affected versions
0.1.0
5.10.0
5.10.1
5.11.0
5.11.1
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
+ 13 more Show less
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.20.0
5.9.2b0
6.0.0
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-28382
PYSEC-2025-256
GHSA-cf8v-5mrc-jv7f
Jun 13, 2025
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
An issue in the openc3-api/tables endpoint of OpenC3 COSMOS before 6.1.0 allows attackers to execute a directory traversal. Affected versions
0.1.0
5.10.0
5.10.1
5.11.0
5.11.1
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
+ 13 more Show less
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.20.0
5.9.2b0
6.0.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-28381
PYSEC-2025-255
Jun 13, 2025
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
A credential leak in OpenC3 COSMOS before v6.0.2 allows attackers to access service credentials as environment variables stored in all containers. Affected versions
0.1.0
5.10.0
5.10.1
5.11.0
5.11.1
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
+ 13 more Show less
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.20.0
5.9.2b0
6.0.0
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-28380
PYSEC-2025-254
Jun 13, 2025
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
A cross-site scripting (XSS) vulnerability in OpenC3 COSMOS before v6.0.2 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the URL parameter. Affected versions
0.1.0
5.10.0
5.10.1
5.11.0
5.11.1
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
+ 13 more Show less
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.20.0
5.9.2b0
6.0.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2024-43795
PYSEC-2024-100
GHSA-vfj8-5pj7-2f9g
Oct 02, 2024
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. The login functionality contains a reflected cross-site scripting (XSS) vulnerability. This vulnerability is fixed in 5.19.0. Note: This CVE only affects Open Source Edition, and not OpenC3 COSMOS Enterprise Edition. Affected versions
0.1.0
5.10.0
5.10.1
5.11.0
5.11.1
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
+ 10 more Show less
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.9.2b0
Fixed in
5.19.0
References Updated Oct 08, 2024 · Source: OSV.dev
CVE-2024-46977
PYSEC-2024-101
GHSA-8jxr-mccc-mwg8
Oct 02, 2024
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. A path traversal vulnerability inside of LocalMode's open_local_file method allows an authenticated user with adequate permissions to download any .txt via the ScreensController#show on the web server COSMOS is running on (depending on the file permissions). This vulnerability is fixed in 5.19.0. Affected versions
0.1.0
5.10.0
5.10.1
5.11.0
5.11.1
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
+ 10 more Show less
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.9.2b0
Fixed in
5.19.0
References Updated Oct 08, 2024 · Source: OSV.dev
CVE-2024-47529
PYSEC-2024-121
GHSA-4xqv-47rm-37mm
Oct 02, 2024
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
High
None
None
OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. OpenC3 COSMOS stores the password of a user unencrypted in the LocalStorage of a web browser. This makes the user password susceptible to exfiltration via Cross-site scripting (see GHSL-2024-128). This vulnerability is fixed in 5.19.0. This only affects Open Source edition, and not OpenC3 COSMOS Enterprise Edition. Affected versions
0.1.0
5.10.0
5.10.1
5.11.0
5.11.1
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
+ 10 more Show less
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.9.2b0
Fixed in
5.19.0
References Updated Nov 13, 2024 · Source: OSV.dev |