openc3
OpenC3 COSMOS
Activity
- Latest release
- 3d ago
- Total releases
- 86
- Cadence
- ~17 days
- Last 12 months
- 21
Reach
- Stars
- 249
Details
- License
- unknown
- First release
- Jul 29, 2022
| Version | Released | |
|---|---|---|
7.4.0
minor
|
7.4.0
minor
Dependencies (62)
+ 54 more
Changelog
Compare changes
|
|
7.3.0
minor
2 CVEs
CVE-2026-42085
GHSA-4jvx-93h3-f45h
PYSEC-2026-2243
Apr 22, 2026
OpenC3 COSMOS allows arbitrary writes to plugins directory via path-traversed config filenames
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
None
SummaryOpenC3 COSMOS contains a design flaw in the DetailsIn function PoC
ImpactModifying the data of other plugins Affected versions
5.0.10
5.0.11
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.10.0
5.10.1
5.11.0
5.11.1
+ 71 more Show less
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.2.0
5.20.0
5.3.0
5.4.0
5.4.1
5.4.2
5.4.3.pre.beta0
5.5.0
5.5.0.pre.beta0
5.5.1
5.5.2
5.5.2.pre.beta0
5.6.0
5.6.1
5.7.0
5.7.2
5.8.0
5.8.1
5.9.0
5.9.1
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
7.0.0
7.0.0.pre.rc1
7.0.0.pre.rc2
7.0.0.pre.rc3
7.0.1
7.1.0
7.1.1
7.2.0
7.2.1
7.3.0
Fixed in
6.10.5
7.0.0-rc3
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-42084
GHSA-wgx6-g857-jjf7
PYSEC-2026-2242
Apr 22, 2026
OpenC3 COSMOS: Hijacked session token can be used to reset password for persistence
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
SummaryThe OpenC3 password change functionality allows a user to change their password without providing the old password, by accepting a valid session token instead. In assumed breach scenarios, this behaviour can be exploited by an attacker who has already obtained a valid session token, to gain persistence in hijacked account (including admin) and prevent legitimate users from accessing the account. DetailsThe design flaw in authentication model (authentication.rb) allows for interchangeable use of password and session tokens for user authentication As old tokens are not revoked upon password reset, an attacker who has obtained a valid session token can continue to authenticate and change the account’s password even after the victim resets it, thereby maintaining persistent control over the compromised account. PoC
ImpactPersistence of an attacker who obtained valid session token and preventing legitimate users from account access Affected versions
5.0.10
5.0.11
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.10.0
5.10.1
5.11.0
5.11.1
+ 71 more Show less
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.2.0
5.20.0
5.3.0
5.4.0
5.4.1
5.4.2
5.4.3.pre.beta0
5.5.0
5.5.0.pre.beta0
5.5.1
5.5.2
5.5.2.pre.beta0
5.6.0
5.6.1
5.7.0
5.7.2
5.8.0
5.8.1
5.9.0
5.9.1
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
7.0.0
7.0.0.pre.rc1
7.0.0.pre.rc2
7.0.0.pre.rc3
7.0.1
7.1.0
7.1.1
7.2.0
7.2.1
7.3.0
Fixed in
6.10.5
7.0.0-rc3
References
Updated Sep 10, 2026 · Source: OSV.dev |
7.3.0
minor
Dependencies (61)
+ 53 more
Changelog
Compare changes
|
|
7.2.1
patch
2 CVEs
CVE-2026-42085
GHSA-4jvx-93h3-f45h
PYSEC-2026-2243
Apr 22, 2026
OpenC3 COSMOS allows arbitrary writes to plugins directory via path-traversed config filenames
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
None
SummaryOpenC3 COSMOS contains a design flaw in the DetailsIn function PoC
ImpactModifying the data of other plugins Affected versions
5.0.10
5.0.11
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.10.0
5.10.1
5.11.0
5.11.1
+ 71 more Show less
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.2.0
5.20.0
5.3.0
5.4.0
5.4.1
5.4.2
5.4.3.pre.beta0
5.5.0
5.5.0.pre.beta0
5.5.1
5.5.2
5.5.2.pre.beta0
5.6.0
5.6.1
5.7.0
5.7.2
5.8.0
5.8.1
5.9.0
5.9.1
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
7.0.0
7.0.0.pre.rc1
7.0.0.pre.rc2
7.0.0.pre.rc3
7.0.1
7.1.0
7.1.1
7.2.0
7.2.1
7.3.0
Fixed in
6.10.5
7.0.0-rc3
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-42084
GHSA-wgx6-g857-jjf7
PYSEC-2026-2242
Apr 22, 2026
OpenC3 COSMOS: Hijacked session token can be used to reset password for persistence
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
SummaryThe OpenC3 password change functionality allows a user to change their password without providing the old password, by accepting a valid session token instead. In assumed breach scenarios, this behaviour can be exploited by an attacker who has already obtained a valid session token, to gain persistence in hijacked account (including admin) and prevent legitimate users from accessing the account. DetailsThe design flaw in authentication model (authentication.rb) allows for interchangeable use of password and session tokens for user authentication As old tokens are not revoked upon password reset, an attacker who has obtained a valid session token can continue to authenticate and change the account’s password even after the victim resets it, thereby maintaining persistent control over the compromised account. PoC
ImpactPersistence of an attacker who obtained valid session token and preventing legitimate users from account access Affected versions
5.0.10
5.0.11
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.10.0
5.10.1
5.11.0
5.11.1
+ 71 more Show less
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.2.0
5.20.0
5.3.0
5.4.0
5.4.1
5.4.2
5.4.3.pre.beta0
5.5.0
5.5.0.pre.beta0
5.5.1
5.5.2
5.5.2.pre.beta0
5.6.0
5.6.1
5.7.0
5.7.2
5.8.0
5.8.1
5.9.0
5.9.1
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
7.0.0
7.0.0.pre.rc1
7.0.0.pre.rc2
7.0.0.pre.rc3
7.0.1
7.1.0
7.1.1
7.2.0
7.2.1
7.3.0
Fixed in
6.10.5
7.0.0-rc3
References
Updated Sep 10, 2026 · Source: OSV.dev |
7.2.1
patch
Dependencies (61)
+ 53 more
Changelog
Compare changes
|
|
7.2.0
minor
2 CVEs
CVE-2026-42085
GHSA-4jvx-93h3-f45h
PYSEC-2026-2243
Apr 22, 2026
OpenC3 COSMOS allows arbitrary writes to plugins directory via path-traversed config filenames
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
None
SummaryOpenC3 COSMOS contains a design flaw in the DetailsIn function PoC
ImpactModifying the data of other plugins Affected versions
5.0.10
5.0.11
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.10.0
5.10.1
5.11.0
5.11.1
+ 71 more Show less
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.2.0
5.20.0
5.3.0
5.4.0
5.4.1
5.4.2
5.4.3.pre.beta0
5.5.0
5.5.0.pre.beta0
5.5.1
5.5.2
5.5.2.pre.beta0
5.6.0
5.6.1
5.7.0
5.7.2
5.8.0
5.8.1
5.9.0
5.9.1
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
7.0.0
7.0.0.pre.rc1
7.0.0.pre.rc2
7.0.0.pre.rc3
7.0.1
7.1.0
7.1.1
7.2.0
7.2.1
7.3.0
Fixed in
6.10.5
7.0.0-rc3
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-42084
GHSA-wgx6-g857-jjf7
PYSEC-2026-2242
Apr 22, 2026
OpenC3 COSMOS: Hijacked session token can be used to reset password for persistence
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
SummaryThe OpenC3 password change functionality allows a user to change their password without providing the old password, by accepting a valid session token instead. In assumed breach scenarios, this behaviour can be exploited by an attacker who has already obtained a valid session token, to gain persistence in hijacked account (including admin) and prevent legitimate users from accessing the account. DetailsThe design flaw in authentication model (authentication.rb) allows for interchangeable use of password and session tokens for user authentication As old tokens are not revoked upon password reset, an attacker who has obtained a valid session token can continue to authenticate and change the account’s password even after the victim resets it, thereby maintaining persistent control over the compromised account. PoC
ImpactPersistence of an attacker who obtained valid session token and preventing legitimate users from account access Affected versions
5.0.10
5.0.11
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.10.0
5.10.1
5.11.0
5.11.1
+ 71 more Show less
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.2.0
5.20.0
5.3.0
5.4.0
5.4.1
5.4.2
5.4.3.pre.beta0
5.5.0
5.5.0.pre.beta0
5.5.1
5.5.2
5.5.2.pre.beta0
5.6.0
5.6.1
5.7.0
5.7.2
5.8.0
5.8.1
5.9.0
5.9.1
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
7.0.0
7.0.0.pre.rc1
7.0.0.pre.rc2
7.0.0.pre.rc3
7.0.1
7.1.0
7.1.1
7.2.0
7.2.1
7.3.0
Fixed in
6.10.5
7.0.0-rc3
References
Updated Sep 10, 2026 · Source: OSV.dev |
7.2.0
minor
Dependencies (61)
+ 53 more
Changelog
Compare changes
|
|
7.1.1
patch
2 CVEs
CVE-2026-42085
GHSA-4jvx-93h3-f45h
PYSEC-2026-2243
Apr 22, 2026
OpenC3 COSMOS allows arbitrary writes to plugins directory via path-traversed config filenames
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
None
SummaryOpenC3 COSMOS contains a design flaw in the DetailsIn function PoC
ImpactModifying the data of other plugins Affected versions
5.0.10
5.0.11
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.10.0
5.10.1
5.11.0
5.11.1
+ 71 more Show less
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.2.0
5.20.0
5.3.0
5.4.0
5.4.1
5.4.2
5.4.3.pre.beta0
5.5.0
5.5.0.pre.beta0
5.5.1
5.5.2
5.5.2.pre.beta0
5.6.0
5.6.1
5.7.0
5.7.2
5.8.0
5.8.1
5.9.0
5.9.1
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
7.0.0
7.0.0.pre.rc1
7.0.0.pre.rc2
7.0.0.pre.rc3
7.0.1
7.1.0
7.1.1
7.2.0
7.2.1
7.3.0
Fixed in
6.10.5
7.0.0-rc3
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-42084
GHSA-wgx6-g857-jjf7
PYSEC-2026-2242
Apr 22, 2026
OpenC3 COSMOS: Hijacked session token can be used to reset password for persistence
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
SummaryThe OpenC3 password change functionality allows a user to change their password without providing the old password, by accepting a valid session token instead. In assumed breach scenarios, this behaviour can be exploited by an attacker who has already obtained a valid session token, to gain persistence in hijacked account (including admin) and prevent legitimate users from accessing the account. DetailsThe design flaw in authentication model (authentication.rb) allows for interchangeable use of password and session tokens for user authentication As old tokens are not revoked upon password reset, an attacker who has obtained a valid session token can continue to authenticate and change the account’s password even after the victim resets it, thereby maintaining persistent control over the compromised account. PoC
ImpactPersistence of an attacker who obtained valid session token and preventing legitimate users from account access Affected versions
5.0.10
5.0.11
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.10.0
5.10.1
5.11.0
5.11.1
+ 71 more Show less
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.2.0
5.20.0
5.3.0
5.4.0
5.4.1
5.4.2
5.4.3.pre.beta0
5.5.0
5.5.0.pre.beta0
5.5.1
5.5.2
5.5.2.pre.beta0
5.6.0
5.6.1
5.7.0
5.7.2
5.8.0
5.8.1
5.9.0
5.9.1
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
7.0.0
7.0.0.pre.rc1
7.0.0.pre.rc2
7.0.0.pre.rc3
7.0.1
7.1.0
7.1.1
7.2.0
7.2.1
7.3.0
Fixed in
6.10.5
7.0.0-rc3
References
Updated Sep 10, 2026 · Source: OSV.dev |
7.1.1
patch
Dependencies (61)
+ 53 more
Changelog
Compare changes
|
|
6.10.6
patch
3 CVEs
CVE-2026-42088
GHSA-2wvh-87g2-89hr
PYSEC-2026-2245
Apr 23, 2026
OpenC3 COSMOS: Permissions Bypass Provides User Access to Unassigned Administrative Actions via Script Runner Tool
9.6
/ 10
Critical
Network
Low
Low
None
Changed
High
High
None
Vulnerability Type: Execution with Unnecessary Privileges Attack type: Authenticated remote Impact: Data disclosure/manipulation, privilege escalation Affected components: The following docker images: • Openc3inc/openc3-COSMOS-script-runner-api The Script Runner widget allows users to execute Python and Ruby scripts directly from the openc3-COSMOS-script-runner-api container. Because all the docker containers share a network, users can execute specially crafted scripts to bypass the API permissions check and perform administrative actions, including reading and modifying data inside the Redis database, which can be used to read secrets and change COSMOS settings, as well as read and write to the buckets service, which holds configuration, log, and plugin files. These actions are normally only available from the Admin Console or with administrative privileges. Any user with permission to create and run scripts can connect to any service in the docker network. Figure 1: Environment variables, including Redis credentials, found in the Script Runner container A Ruby script is used to expose the Redis username, password, hostname, and port. These credentials might also be found from the source code or through a brute-force attack. Figure 2: A Python script is used to add data to Redis and retrieve the new data
A Python script is then used to create a new entry in the Redis database called Figure 3: The new data found in the Redis database
The new entry was successfully added to the Redis database, as is confirmed by using Figure 4: Uploading file to change the plugin store URL setting Figure 5: The URL file was successfully changed Steps To Reproduce
Recommendations• Limit the permissions of the script runner API to prevent lower level users from performing administrative actions Affected versions
5.0.10
5.0.11
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.10.0
5.10.1
5.11.0
5.11.1
+ 63 more Show less
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.2.0
5.20.0
5.3.0
5.4.0
5.4.1
5.4.2
5.4.3.pre.beta0
5.5.0
5.5.0.pre.beta0
5.5.1
5.5.2
5.5.2.pre.beta0
5.6.0
5.6.1
5.7.0
5.7.2
5.8.0
5.8.1
5.9.0
5.9.1
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.10.5
6.10.6
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
Fixed in
7.0.0-rc3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-42087
GHSA-v529-vhwc-wfc5
PYSEC-2026-2244
Apr 23, 2026
OpenC3 COSMOS has SQL Injection in QuestDB Time-Series Database
9.6
/ 10
Critical
Network
Low
Low
None
Changed
High
High
None
Vulnerability Type: CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Attack type: Authenticated remote Impact: Telemetry data disclosure and deletion Affected components: openc3-tsdb (QuestDB) A SQL injection vulnerability exists in the Time-Series Database (TSDB) component of COSMOS. The Figure 1: Source code vulnerable to SQL injection
Additionally, the Figure 2: Source code showing the required permissions for the Figure 3: A normal request to the Figure 4: The request and response after sending the SQL injection payload This payload can be modified to executes SQL commands in the TSDB. Figure 5: SQL injection used to execute arbitrary SQL command The user can then delete all the historical data in the database: Figure 6: Example payload dropping the tables Steps to Reproduce
Recommendations• Sanitize all user-supplied input before executing it • Use prepared statements with parameterized queries when executing SQL statements Affected versions
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.10.5
6.10.6
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
+ 1 more Show less
6.9.2
Fixed in
7.0.0-rc3
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-42086
GHSA-ffq5-qpvf-xq7x
PYSEC-2026-105
Apr 22, 2026
OpenC3 COSMOS is Vulnerable to Self-XSS Through the Command Sender
4.6
/ 10
Medium
Network
Low
Low
Required
Unchanged
Low
Low
None
SummaryThe Command Sender UI uses an unsafe DetailsThe unsafe PoC
Below example uses ImpactLocal JavaScript execution in the user's browser Affected versions
5.0.10
5.0.11
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.10.0
5.10.1
5.11.0
5.11.1
+ 66 more Show less
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.2.0
5.20.0
5.3.0
5.4.0
5.4.1
5.4.2
5.4.3.pre.beta0
5.5.0
5.5.0.pre.beta0
5.5.1
5.5.2
5.5.2.pre.beta0
5.6.0
5.6.1
5.7.0
5.7.2
5.8.0
5.8.1
5.9.0
5.9.1
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.10.5
6.10.6
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
7.0.0.pre.rc1
7.0.0.pre.rc2
7.0.0.pre.rc3
Fixed in
7.0.0
References
Updated May 29, 2026 · Source: OSV.dev |
6.10.6
patch
Dependencies (59)
+ 51 more
Changelog
Compare changes
|
|
7.1.0
minor
2 CVEs
CVE-2026-42085
GHSA-4jvx-93h3-f45h
PYSEC-2026-2243
Apr 22, 2026
OpenC3 COSMOS allows arbitrary writes to plugins directory via path-traversed config filenames
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
None
SummaryOpenC3 COSMOS contains a design flaw in the DetailsIn function PoC
ImpactModifying the data of other plugins Affected versions
5.0.10
5.0.11
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.10.0
5.10.1
5.11.0
5.11.1
+ 71 more Show less
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.2.0
5.20.0
5.3.0
5.4.0
5.4.1
5.4.2
5.4.3.pre.beta0
5.5.0
5.5.0.pre.beta0
5.5.1
5.5.2
5.5.2.pre.beta0
5.6.0
5.6.1
5.7.0
5.7.2
5.8.0
5.8.1
5.9.0
5.9.1
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
7.0.0
7.0.0.pre.rc1
7.0.0.pre.rc2
7.0.0.pre.rc3
7.0.1
7.1.0
7.1.1
7.2.0
7.2.1
7.3.0
Fixed in
6.10.5
7.0.0-rc3
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-42084
GHSA-wgx6-g857-jjf7
PYSEC-2026-2242
Apr 22, 2026
OpenC3 COSMOS: Hijacked session token can be used to reset password for persistence
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
SummaryThe OpenC3 password change functionality allows a user to change their password without providing the old password, by accepting a valid session token instead. In assumed breach scenarios, this behaviour can be exploited by an attacker who has already obtained a valid session token, to gain persistence in hijacked account (including admin) and prevent legitimate users from accessing the account. DetailsThe design flaw in authentication model (authentication.rb) allows for interchangeable use of password and session tokens for user authentication As old tokens are not revoked upon password reset, an attacker who has obtained a valid session token can continue to authenticate and change the account’s password even after the victim resets it, thereby maintaining persistent control over the compromised account. PoC
ImpactPersistence of an attacker who obtained valid session token and preventing legitimate users from account access Affected versions
5.0.10
5.0.11
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.10.0
5.10.1
5.11.0
5.11.1
+ 71 more Show less
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.2.0
5.20.0
5.3.0
5.4.0
5.4.1
5.4.2
5.4.3.pre.beta0
5.5.0
5.5.0.pre.beta0
5.5.1
5.5.2
5.5.2.pre.beta0
5.6.0
5.6.1
5.7.0
5.7.2
5.8.0
5.8.1
5.9.0
5.9.1
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
7.0.0
7.0.0.pre.rc1
7.0.0.pre.rc2
7.0.0.pre.rc3
7.0.1
7.1.0
7.1.1
7.2.0
7.2.1
7.3.0
Fixed in
6.10.5
7.0.0-rc3
References
Updated Sep 10, 2026 · Source: OSV.dev |
7.1.0
minor
Dependencies (61)
+ 53 more
Changelog
Compare changes
|
|
6.10.5
patch
3 CVEs
CVE-2026-42088
GHSA-2wvh-87g2-89hr
PYSEC-2026-2245
Apr 23, 2026
OpenC3 COSMOS: Permissions Bypass Provides User Access to Unassigned Administrative Actions via Script Runner Tool
9.6
/ 10
Critical
Network
Low
Low
None
Changed
High
High
None
Vulnerability Type: Execution with Unnecessary Privileges Attack type: Authenticated remote Impact: Data disclosure/manipulation, privilege escalation Affected components: The following docker images: • Openc3inc/openc3-COSMOS-script-runner-api The Script Runner widget allows users to execute Python and Ruby scripts directly from the openc3-COSMOS-script-runner-api container. Because all the docker containers share a network, users can execute specially crafted scripts to bypass the API permissions check and perform administrative actions, including reading and modifying data inside the Redis database, which can be used to read secrets and change COSMOS settings, as well as read and write to the buckets service, which holds configuration, log, and plugin files. These actions are normally only available from the Admin Console or with administrative privileges. Any user with permission to create and run scripts can connect to any service in the docker network. Figure 1: Environment variables, including Redis credentials, found in the Script Runner container A Ruby script is used to expose the Redis username, password, hostname, and port. These credentials might also be found from the source code or through a brute-force attack. Figure 2: A Python script is used to add data to Redis and retrieve the new data
A Python script is then used to create a new entry in the Redis database called Figure 3: The new data found in the Redis database
The new entry was successfully added to the Redis database, as is confirmed by using Figure 4: Uploading file to change the plugin store URL setting Figure 5: The URL file was successfully changed Steps To Reproduce
Recommendations• Limit the permissions of the script runner API to prevent lower level users from performing administrative actions Affected versions
5.0.10
5.0.11
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.10.0
5.10.1
5.11.0
5.11.1
+ 63 more Show less
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.2.0
5.20.0
5.3.0
5.4.0
5.4.1
5.4.2
5.4.3.pre.beta0
5.5.0
5.5.0.pre.beta0
5.5.1
5.5.2
5.5.2.pre.beta0
5.6.0
5.6.1
5.7.0
5.7.2
5.8.0
5.8.1
5.9.0
5.9.1
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.10.5
6.10.6
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
Fixed in
7.0.0-rc3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-42087
GHSA-v529-vhwc-wfc5
PYSEC-2026-2244
Apr 23, 2026
OpenC3 COSMOS has SQL Injection in QuestDB Time-Series Database
9.6
/ 10
Critical
Network
Low
Low
None
Changed
High
High
None
Vulnerability Type: CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Attack type: Authenticated remote Impact: Telemetry data disclosure and deletion Affected components: openc3-tsdb (QuestDB) A SQL injection vulnerability exists in the Time-Series Database (TSDB) component of COSMOS. The Figure 1: Source code vulnerable to SQL injection
Additionally, the Figure 2: Source code showing the required permissions for the Figure 3: A normal request to the Figure 4: The request and response after sending the SQL injection payload This payload can be modified to executes SQL commands in the TSDB. Figure 5: SQL injection used to execute arbitrary SQL command The user can then delete all the historical data in the database: Figure 6: Example payload dropping the tables Steps to Reproduce
Recommendations• Sanitize all user-supplied input before executing it • Use prepared statements with parameterized queries when executing SQL statements Affected versions
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.10.5
6.10.6
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
+ 1 more Show less
6.9.2
Fixed in
7.0.0-rc3
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-42086
GHSA-ffq5-qpvf-xq7x
PYSEC-2026-105
Apr 22, 2026
OpenC3 COSMOS is Vulnerable to Self-XSS Through the Command Sender
4.6
/ 10
Medium
Network
Low
Low
Required
Unchanged
Low
Low
None
SummaryThe Command Sender UI uses an unsafe DetailsThe unsafe PoC
Below example uses ImpactLocal JavaScript execution in the user's browser Affected versions
5.0.10
5.0.11
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.10.0
5.10.1
5.11.0
5.11.1
+ 66 more Show less
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.2.0
5.20.0
5.3.0
5.4.0
5.4.1
5.4.2
5.4.3.pre.beta0
5.5.0
5.5.0.pre.beta0
5.5.1
5.5.2
5.5.2.pre.beta0
5.6.0
5.6.1
5.7.0
5.7.2
5.8.0
5.8.1
5.9.0
5.9.1
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.10.5
6.10.6
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
7.0.0.pre.rc1
7.0.0.pre.rc2
7.0.0.pre.rc3
Fixed in
7.0.0
References
Updated May 29, 2026 · Source: OSV.dev |
6.10.5
patch
Dependencies (59)
+ 51 more
Changelog
Compare changes
|
|
7.0.1
patch
2 CVEs
CVE-2026-42085
GHSA-4jvx-93h3-f45h
PYSEC-2026-2243
Apr 22, 2026
OpenC3 COSMOS allows arbitrary writes to plugins directory via path-traversed config filenames
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
None
SummaryOpenC3 COSMOS contains a design flaw in the DetailsIn function PoC
ImpactModifying the data of other plugins Affected versions
5.0.10
5.0.11
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.10.0
5.10.1
5.11.0
5.11.1
+ 71 more Show less
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.2.0
5.20.0
5.3.0
5.4.0
5.4.1
5.4.2
5.4.3.pre.beta0
5.5.0
5.5.0.pre.beta0
5.5.1
5.5.2
5.5.2.pre.beta0
5.6.0
5.6.1
5.7.0
5.7.2
5.8.0
5.8.1
5.9.0
5.9.1
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
7.0.0
7.0.0.pre.rc1
7.0.0.pre.rc2
7.0.0.pre.rc3
7.0.1
7.1.0
7.1.1
7.2.0
7.2.1
7.3.0
Fixed in
6.10.5
7.0.0-rc3
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-42084
GHSA-wgx6-g857-jjf7
PYSEC-2026-2242
Apr 22, 2026
OpenC3 COSMOS: Hijacked session token can be used to reset password for persistence
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
SummaryThe OpenC3 password change functionality allows a user to change their password without providing the old password, by accepting a valid session token instead. In assumed breach scenarios, this behaviour can be exploited by an attacker who has already obtained a valid session token, to gain persistence in hijacked account (including admin) and prevent legitimate users from accessing the account. DetailsThe design flaw in authentication model (authentication.rb) allows for interchangeable use of password and session tokens for user authentication As old tokens are not revoked upon password reset, an attacker who has obtained a valid session token can continue to authenticate and change the account’s password even after the victim resets it, thereby maintaining persistent control over the compromised account. PoC
ImpactPersistence of an attacker who obtained valid session token and preventing legitimate users from account access Affected versions
5.0.10
5.0.11
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.10.0
5.10.1
5.11.0
5.11.1
+ 71 more Show less
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.2.0
5.20.0
5.3.0
5.4.0
5.4.1
5.4.2
5.4.3.pre.beta0
5.5.0
5.5.0.pre.beta0
5.5.1
5.5.2
5.5.2.pre.beta0
5.6.0
5.6.1
5.7.0
5.7.2
5.8.0
5.8.1
5.9.0
5.9.1
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
7.0.0
7.0.0.pre.rc1
7.0.0.pre.rc2
7.0.0.pre.rc3
7.0.1
7.1.0
7.1.1
7.2.0
7.2.1
7.3.0
Fixed in
6.10.5
7.0.0-rc3
References
Updated Sep 10, 2026 · Source: OSV.dev |
7.0.1
patch
Dependencies (61)
+ 53 more
Changelog
Compare changes
|
|
7.0.0
major
2 CVEs
CVE-2026-42085
GHSA-4jvx-93h3-f45h
PYSEC-2026-2243
Apr 22, 2026
OpenC3 COSMOS allows arbitrary writes to plugins directory via path-traversed config filenames
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
None
SummaryOpenC3 COSMOS contains a design flaw in the DetailsIn function PoC
ImpactModifying the data of other plugins Affected versions
5.0.10
5.0.11
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.10.0
5.10.1
5.11.0
5.11.1
+ 71 more Show less
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.2.0
5.20.0
5.3.0
5.4.0
5.4.1
5.4.2
5.4.3.pre.beta0
5.5.0
5.5.0.pre.beta0
5.5.1
5.5.2
5.5.2.pre.beta0
5.6.0
5.6.1
5.7.0
5.7.2
5.8.0
5.8.1
5.9.0
5.9.1
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
7.0.0
7.0.0.pre.rc1
7.0.0.pre.rc2
7.0.0.pre.rc3
7.0.1
7.1.0
7.1.1
7.2.0
7.2.1
7.3.0
Fixed in
6.10.5
7.0.0-rc3
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-42084
GHSA-wgx6-g857-jjf7
PYSEC-2026-2242
Apr 22, 2026
OpenC3 COSMOS: Hijacked session token can be used to reset password for persistence
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
SummaryThe OpenC3 password change functionality allows a user to change their password without providing the old password, by accepting a valid session token instead. In assumed breach scenarios, this behaviour can be exploited by an attacker who has already obtained a valid session token, to gain persistence in hijacked account (including admin) and prevent legitimate users from accessing the account. DetailsThe design flaw in authentication model (authentication.rb) allows for interchangeable use of password and session tokens for user authentication As old tokens are not revoked upon password reset, an attacker who has obtained a valid session token can continue to authenticate and change the account’s password even after the victim resets it, thereby maintaining persistent control over the compromised account. PoC
ImpactPersistence of an attacker who obtained valid session token and preventing legitimate users from account access Affected versions
5.0.10
5.0.11
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.10.0
5.10.1
5.11.0
5.11.1
+ 71 more Show less
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.2.0
5.20.0
5.3.0
5.4.0
5.4.1
5.4.2
5.4.3.pre.beta0
5.5.0
5.5.0.pre.beta0
5.5.1
5.5.2
5.5.2.pre.beta0
5.6.0
5.6.1
5.7.0
5.7.2
5.8.0
5.8.1
5.9.0
5.9.1
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
7.0.0
7.0.0.pre.rc1
7.0.0.pre.rc2
7.0.0.pre.rc3
7.0.1
7.1.0
7.1.1
7.2.0
7.2.1
7.3.0
Fixed in
6.10.5
7.0.0-rc3
References
Updated Sep 10, 2026 · Source: OSV.dev |
7.0.0
major
Dependencies (61)
+ 53 more
Changelog
Compare changes
|
|
7.0.0.pre.rc3
pre
5 CVEs
CVE-2026-42088
GHSA-2wvh-87g2-89hr
PYSEC-2026-2245
Apr 23, 2026
OpenC3 COSMOS: Permissions Bypass Provides User Access to Unassigned Administrative Actions via Script Runner Tool
9.6
/ 10
Critical
Network
Low
Low
None
Changed
High
High
None
Vulnerability Type: Execution with Unnecessary Privileges Attack type: Authenticated remote Impact: Data disclosure/manipulation, privilege escalation Affected components: The following docker images: • Openc3inc/openc3-COSMOS-script-runner-api The Script Runner widget allows users to execute Python and Ruby scripts directly from the openc3-COSMOS-script-runner-api container. Because all the docker containers share a network, users can execute specially crafted scripts to bypass the API permissions check and perform administrative actions, including reading and modifying data inside the Redis database, which can be used to read secrets and change COSMOS settings, as well as read and write to the buckets service, which holds configuration, log, and plugin files. These actions are normally only available from the Admin Console or with administrative privileges. Any user with permission to create and run scripts can connect to any service in the docker network. Figure 1: Environment variables, including Redis credentials, found in the Script Runner container A Ruby script is used to expose the Redis username, password, hostname, and port. These credentials might also be found from the source code or through a brute-force attack. Figure 2: A Python script is used to add data to Redis and retrieve the new data
A Python script is then used to create a new entry in the Redis database called Figure 3: The new data found in the Redis database
The new entry was successfully added to the Redis database, as is confirmed by using Figure 4: Uploading file to change the plugin store URL setting Figure 5: The URL file was successfully changed Steps To Reproduce
Recommendations• Limit the permissions of the script runner API to prevent lower level users from performing administrative actions Affected versions
5.0.10
5.0.11
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.10.0
5.10.1
5.11.0
5.11.1
+ 63 more Show less
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.2.0
5.20.0
5.3.0
5.4.0
5.4.1
5.4.2
5.4.3.pre.beta0
5.5.0
5.5.0.pre.beta0
5.5.1
5.5.2
5.5.2.pre.beta0
5.6.0
5.6.1
5.7.0
5.7.2
5.8.0
5.8.1
5.9.0
5.9.1
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.10.5
6.10.6
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
Fixed in
7.0.0-rc3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-42087
GHSA-v529-vhwc-wfc5
PYSEC-2026-2244
Apr 23, 2026
OpenC3 COSMOS has SQL Injection in QuestDB Time-Series Database
9.6
/ 10
Critical
Network
Low
Low
None
Changed
High
High
None
Vulnerability Type: CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Attack type: Authenticated remote Impact: Telemetry data disclosure and deletion Affected components: openc3-tsdb (QuestDB) A SQL injection vulnerability exists in the Time-Series Database (TSDB) component of COSMOS. The Figure 1: Source code vulnerable to SQL injection
Additionally, the Figure 2: Source code showing the required permissions for the Figure 3: A normal request to the Figure 4: The request and response after sending the SQL injection payload This payload can be modified to executes SQL commands in the TSDB. Figure 5: SQL injection used to execute arbitrary SQL command The user can then delete all the historical data in the database: Figure 6: Example payload dropping the tables Steps to Reproduce
Recommendations• Sanitize all user-supplied input before executing it • Use prepared statements with parameterized queries when executing SQL statements Affected versions
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.10.5
6.10.6
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
+ 1 more Show less
6.9.2
Fixed in
7.0.0-rc3
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-42086
GHSA-ffq5-qpvf-xq7x
PYSEC-2026-105
Apr 22, 2026
OpenC3 COSMOS is Vulnerable to Self-XSS Through the Command Sender
4.6
/ 10
Medium
Network
Low
Low
Required
Unchanged
Low
Low
None
SummaryThe Command Sender UI uses an unsafe DetailsThe unsafe PoC
Below example uses ImpactLocal JavaScript execution in the user's browser Affected versions
5.0.10
5.0.11
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.10.0
5.10.1
5.11.0
5.11.1
+ 66 more Show less
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.2.0
5.20.0
5.3.0
5.4.0
5.4.1
5.4.2
5.4.3.pre.beta0
5.5.0
5.5.0.pre.beta0
5.5.1
5.5.2
5.5.2.pre.beta0
5.6.0
5.6.1
5.7.0
5.7.2
5.8.0
5.8.1
5.9.0
5.9.1
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.10.5
6.10.6
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
7.0.0.pre.rc1
7.0.0.pre.rc2
7.0.0.pre.rc3
Fixed in
7.0.0
References
Updated May 29, 2026 · Source: OSV.dev
CVE-2026-42085
GHSA-4jvx-93h3-f45h
PYSEC-2026-2243
Apr 22, 2026
OpenC3 COSMOS allows arbitrary writes to plugins directory via path-traversed config filenames
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
None
SummaryOpenC3 COSMOS contains a design flaw in the DetailsIn function PoC
ImpactModifying the data of other plugins Affected versions
5.0.10
5.0.11
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.10.0
5.10.1
5.11.0
5.11.1
+ 71 more Show less
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.2.0
5.20.0
5.3.0
5.4.0
5.4.1
5.4.2
5.4.3.pre.beta0
5.5.0
5.5.0.pre.beta0
5.5.1
5.5.2
5.5.2.pre.beta0
5.6.0
5.6.1
5.7.0
5.7.2
5.8.0
5.8.1
5.9.0
5.9.1
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
7.0.0
7.0.0.pre.rc1
7.0.0.pre.rc2
7.0.0.pre.rc3
7.0.1
7.1.0
7.1.1
7.2.0
7.2.1
7.3.0
Fixed in
6.10.5
7.0.0-rc3
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-42084
GHSA-wgx6-g857-jjf7
PYSEC-2026-2242
Apr 22, 2026
OpenC3 COSMOS: Hijacked session token can be used to reset password for persistence
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
SummaryThe OpenC3 password change functionality allows a user to change their password without providing the old password, by accepting a valid session token instead. In assumed breach scenarios, this behaviour can be exploited by an attacker who has already obtained a valid session token, to gain persistence in hijacked account (including admin) and prevent legitimate users from accessing the account. DetailsThe design flaw in authentication model (authentication.rb) allows for interchangeable use of password and session tokens for user authentication As old tokens are not revoked upon password reset, an attacker who has obtained a valid session token can continue to authenticate and change the account’s password even after the victim resets it, thereby maintaining persistent control over the compromised account. PoC
ImpactPersistence of an attacker who obtained valid session token and preventing legitimate users from account access Affected versions
5.0.10
5.0.11
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.10.0
5.10.1
5.11.0
5.11.1
+ 71 more Show less
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.2.0
5.20.0
5.3.0
5.4.0
5.4.1
5.4.2
5.4.3.pre.beta0
5.5.0
5.5.0.pre.beta0
5.5.1
5.5.2
5.5.2.pre.beta0
5.6.0
5.6.1
5.7.0
5.7.2
5.8.0
5.8.1
5.9.0
5.9.1
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
7.0.0
7.0.0.pre.rc1
7.0.0.pre.rc2
7.0.0.pre.rc3
7.0.1
7.1.0
7.1.1
7.2.0
7.2.1
7.3.0
Fixed in
6.10.5
7.0.0-rc3
References
Updated Sep 10, 2026 · Source: OSV.dev |
7.0.0.pre.rc3
pre
Dependencies (60)
+ 52 more
Changelog
Compare changes
|
|
7.0.0.pre.rc2
pre
5 CVEs
CVE-2026-42088
GHSA-2wvh-87g2-89hr
PYSEC-2026-2245
Apr 23, 2026
OpenC3 COSMOS: Permissions Bypass Provides User Access to Unassigned Administrative Actions via Script Runner Tool
9.6
/ 10
Critical
Network
Low
Low
None
Changed
High
High
None
Vulnerability Type: Execution with Unnecessary Privileges Attack type: Authenticated remote Impact: Data disclosure/manipulation, privilege escalation Affected components: The following docker images: • Openc3inc/openc3-COSMOS-script-runner-api The Script Runner widget allows users to execute Python and Ruby scripts directly from the openc3-COSMOS-script-runner-api container. Because all the docker containers share a network, users can execute specially crafted scripts to bypass the API permissions check and perform administrative actions, including reading and modifying data inside the Redis database, which can be used to read secrets and change COSMOS settings, as well as read and write to the buckets service, which holds configuration, log, and plugin files. These actions are normally only available from the Admin Console or with administrative privileges. Any user with permission to create and run scripts can connect to any service in the docker network. Figure 1: Environment variables, including Redis credentials, found in the Script Runner container A Ruby script is used to expose the Redis username, password, hostname, and port. These credentials might also be found from the source code or through a brute-force attack. Figure 2: A Python script is used to add data to Redis and retrieve the new data
A Python script is then used to create a new entry in the Redis database called Figure 3: The new data found in the Redis database
The new entry was successfully added to the Redis database, as is confirmed by using Figure 4: Uploading file to change the plugin store URL setting Figure 5: The URL file was successfully changed Steps To Reproduce
Recommendations• Limit the permissions of the script runner API to prevent lower level users from performing administrative actions Affected versions
5.0.10
5.0.11
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.10.0
5.10.1
5.11.0
5.11.1
+ 63 more Show less
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.2.0
5.20.0
5.3.0
5.4.0
5.4.1
5.4.2
5.4.3.pre.beta0
5.5.0
5.5.0.pre.beta0
5.5.1
5.5.2
5.5.2.pre.beta0
5.6.0
5.6.1
5.7.0
5.7.2
5.8.0
5.8.1
5.9.0
5.9.1
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.10.5
6.10.6
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
Fixed in
7.0.0-rc3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-42087
GHSA-v529-vhwc-wfc5
PYSEC-2026-2244
Apr 23, 2026
OpenC3 COSMOS has SQL Injection in QuestDB Time-Series Database
9.6
/ 10
Critical
Network
Low
Low
None
Changed
High
High
None
Vulnerability Type: CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Attack type: Authenticated remote Impact: Telemetry data disclosure and deletion Affected components: openc3-tsdb (QuestDB) A SQL injection vulnerability exists in the Time-Series Database (TSDB) component of COSMOS. The Figure 1: Source code vulnerable to SQL injection
Additionally, the Figure 2: Source code showing the required permissions for the Figure 3: A normal request to the Figure 4: The request and response after sending the SQL injection payload This payload can be modified to executes SQL commands in the TSDB. Figure 5: SQL injection used to execute arbitrary SQL command The user can then delete all the historical data in the database: Figure 6: Example payload dropping the tables Steps to Reproduce
Recommendations• Sanitize all user-supplied input before executing it • Use prepared statements with parameterized queries when executing SQL statements Affected versions
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.10.5
6.10.6
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
+ 1 more Show less
6.9.2
Fixed in
7.0.0-rc3
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-42086
GHSA-ffq5-qpvf-xq7x
PYSEC-2026-105
Apr 22, 2026
OpenC3 COSMOS is Vulnerable to Self-XSS Through the Command Sender
4.6
/ 10
Medium
Network
Low
Low
Required
Unchanged
Low
Low
None
SummaryThe Command Sender UI uses an unsafe DetailsThe unsafe PoC
Below example uses ImpactLocal JavaScript execution in the user's browser Affected versions
5.0.10
5.0.11
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.10.0
5.10.1
5.11.0
5.11.1
+ 66 more Show less
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.2.0
5.20.0
5.3.0
5.4.0
5.4.1
5.4.2
5.4.3.pre.beta0
5.5.0
5.5.0.pre.beta0
5.5.1
5.5.2
5.5.2.pre.beta0
5.6.0
5.6.1
5.7.0
5.7.2
5.8.0
5.8.1
5.9.0
5.9.1
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.10.5
6.10.6
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
7.0.0.pre.rc1
7.0.0.pre.rc2
7.0.0.pre.rc3
Fixed in
7.0.0
References
Updated May 29, 2026 · Source: OSV.dev
CVE-2026-42085
GHSA-4jvx-93h3-f45h
PYSEC-2026-2243
Apr 22, 2026
OpenC3 COSMOS allows arbitrary writes to plugins directory via path-traversed config filenames
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
None
SummaryOpenC3 COSMOS contains a design flaw in the DetailsIn function PoC
ImpactModifying the data of other plugins Affected versions
5.0.10
5.0.11
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.10.0
5.10.1
5.11.0
5.11.1
+ 71 more Show less
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.2.0
5.20.0
5.3.0
5.4.0
5.4.1
5.4.2
5.4.3.pre.beta0
5.5.0
5.5.0.pre.beta0
5.5.1
5.5.2
5.5.2.pre.beta0
5.6.0
5.6.1
5.7.0
5.7.2
5.8.0
5.8.1
5.9.0
5.9.1
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
7.0.0
7.0.0.pre.rc1
7.0.0.pre.rc2
7.0.0.pre.rc3
7.0.1
7.1.0
7.1.1
7.2.0
7.2.1
7.3.0
Fixed in
6.10.5
7.0.0-rc3
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-42084
GHSA-wgx6-g857-jjf7
PYSEC-2026-2242
Apr 22, 2026
OpenC3 COSMOS: Hijacked session token can be used to reset password for persistence
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
SummaryThe OpenC3 password change functionality allows a user to change their password without providing the old password, by accepting a valid session token instead. In assumed breach scenarios, this behaviour can be exploited by an attacker who has already obtained a valid session token, to gain persistence in hijacked account (including admin) and prevent legitimate users from accessing the account. DetailsThe design flaw in authentication model (authentication.rb) allows for interchangeable use of password and session tokens for user authentication As old tokens are not revoked upon password reset, an attacker who has obtained a valid session token can continue to authenticate and change the account’s password even after the victim resets it, thereby maintaining persistent control over the compromised account. PoC
ImpactPersistence of an attacker who obtained valid session token and preventing legitimate users from account access Affected versions
5.0.10
5.0.11
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.10.0
5.10.1
5.11.0
5.11.1
+ 71 more Show less
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.2.0
5.20.0
5.3.0
5.4.0
5.4.1
5.4.2
5.4.3.pre.beta0
5.5.0
5.5.0.pre.beta0
5.5.1
5.5.2
5.5.2.pre.beta0
5.6.0
5.6.1
5.7.0
5.7.2
5.8.0
5.8.1
5.9.0
5.9.1
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
7.0.0
7.0.0.pre.rc1
7.0.0.pre.rc2
7.0.0.pre.rc3
7.0.1
7.1.0
7.1.1
7.2.0
7.2.1
7.3.0
Fixed in
6.10.5
7.0.0-rc3
References
Updated Sep 10, 2026 · Source: OSV.dev |
7.0.0.pre.rc2
pre
Dependencies (61)
+ 53 more
Changelog
Compare changes
|
|
7.0.0.pre.rc1
pre
5 CVEs
CVE-2026-42088
GHSA-2wvh-87g2-89hr
PYSEC-2026-2245
Apr 23, 2026
OpenC3 COSMOS: Permissions Bypass Provides User Access to Unassigned Administrative Actions via Script Runner Tool
9.6
/ 10
Critical
Network
Low
Low
None
Changed
High
High
None
Vulnerability Type: Execution with Unnecessary Privileges Attack type: Authenticated remote Impact: Data disclosure/manipulation, privilege escalation Affected components: The following docker images: • Openc3inc/openc3-COSMOS-script-runner-api The Script Runner widget allows users to execute Python and Ruby scripts directly from the openc3-COSMOS-script-runner-api container. Because all the docker containers share a network, users can execute specially crafted scripts to bypass the API permissions check and perform administrative actions, including reading and modifying data inside the Redis database, which can be used to read secrets and change COSMOS settings, as well as read and write to the buckets service, which holds configuration, log, and plugin files. These actions are normally only available from the Admin Console or with administrative privileges. Any user with permission to create and run scripts can connect to any service in the docker network. Figure 1: Environment variables, including Redis credentials, found in the Script Runner container A Ruby script is used to expose the Redis username, password, hostname, and port. These credentials might also be found from the source code or through a brute-force attack. Figure 2: A Python script is used to add data to Redis and retrieve the new data
A Python script is then used to create a new entry in the Redis database called Figure 3: The new data found in the Redis database
The new entry was successfully added to the Redis database, as is confirmed by using Figure 4: Uploading file to change the plugin store URL setting Figure 5: The URL file was successfully changed Steps To Reproduce
Recommendations• Limit the permissions of the script runner API to prevent lower level users from performing administrative actions Affected versions
5.0.10
5.0.11
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.10.0
5.10.1
5.11.0
5.11.1
+ 63 more Show less
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.2.0
5.20.0
5.3.0
5.4.0
5.4.1
5.4.2
5.4.3.pre.beta0
5.5.0
5.5.0.pre.beta0
5.5.1
5.5.2
5.5.2.pre.beta0
5.6.0
5.6.1
5.7.0
5.7.2
5.8.0
5.8.1
5.9.0
5.9.1
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.10.5
6.10.6
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
Fixed in
7.0.0-rc3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-42087
GHSA-v529-vhwc-wfc5
PYSEC-2026-2244
Apr 23, 2026
OpenC3 COSMOS has SQL Injection in QuestDB Time-Series Database
9.6
/ 10
Critical
Network
Low
Low
None
Changed
High
High
None
Vulnerability Type: CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Attack type: Authenticated remote Impact: Telemetry data disclosure and deletion Affected components: openc3-tsdb (QuestDB) A SQL injection vulnerability exists in the Time-Series Database (TSDB) component of COSMOS. The Figure 1: Source code vulnerable to SQL injection
Additionally, the Figure 2: Source code showing the required permissions for the Figure 3: A normal request to the Figure 4: The request and response after sending the SQL injection payload This payload can be modified to executes SQL commands in the TSDB. Figure 5: SQL injection used to execute arbitrary SQL command The user can then delete all the historical data in the database: Figure 6: Example payload dropping the tables Steps to Reproduce
Recommendations• Sanitize all user-supplied input before executing it • Use prepared statements with parameterized queries when executing SQL statements Affected versions
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.10.5
6.10.6
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
+ 1 more Show less
6.9.2
Fixed in
7.0.0-rc3
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-42086
GHSA-ffq5-qpvf-xq7x
PYSEC-2026-105
Apr 22, 2026
OpenC3 COSMOS is Vulnerable to Self-XSS Through the Command Sender
4.6
/ 10
Medium
Network
Low
Low
Required
Unchanged
Low
Low
None
SummaryThe Command Sender UI uses an unsafe DetailsThe unsafe PoC
Below example uses ImpactLocal JavaScript execution in the user's browser Affected versions
5.0.10
5.0.11
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.10.0
5.10.1
5.11.0
5.11.1
+ 66 more Show less
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.2.0
5.20.0
5.3.0
5.4.0
5.4.1
5.4.2
5.4.3.pre.beta0
5.5.0
5.5.0.pre.beta0
5.5.1
5.5.2
5.5.2.pre.beta0
5.6.0
5.6.1
5.7.0
5.7.2
5.8.0
5.8.1
5.9.0
5.9.1
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.10.5
6.10.6
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
7.0.0.pre.rc1
7.0.0.pre.rc2
7.0.0.pre.rc3
Fixed in
7.0.0
References
Updated May 29, 2026 · Source: OSV.dev
CVE-2026-42085
GHSA-4jvx-93h3-f45h
PYSEC-2026-2243
Apr 22, 2026
OpenC3 COSMOS allows arbitrary writes to plugins directory via path-traversed config filenames
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
None
SummaryOpenC3 COSMOS contains a design flaw in the DetailsIn function PoC
ImpactModifying the data of other plugins Affected versions
5.0.10
5.0.11
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.10.0
5.10.1
5.11.0
5.11.1
+ 71 more Show less
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.2.0
5.20.0
5.3.0
5.4.0
5.4.1
5.4.2
5.4.3.pre.beta0
5.5.0
5.5.0.pre.beta0
5.5.1
5.5.2
5.5.2.pre.beta0
5.6.0
5.6.1
5.7.0
5.7.2
5.8.0
5.8.1
5.9.0
5.9.1
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
7.0.0
7.0.0.pre.rc1
7.0.0.pre.rc2
7.0.0.pre.rc3
7.0.1
7.1.0
7.1.1
7.2.0
7.2.1
7.3.0
Fixed in
6.10.5
7.0.0-rc3
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-42084
GHSA-wgx6-g857-jjf7
PYSEC-2026-2242
Apr 22, 2026
OpenC3 COSMOS: Hijacked session token can be used to reset password for persistence
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
SummaryThe OpenC3 password change functionality allows a user to change their password without providing the old password, by accepting a valid session token instead. In assumed breach scenarios, this behaviour can be exploited by an attacker who has already obtained a valid session token, to gain persistence in hijacked account (including admin) and prevent legitimate users from accessing the account. DetailsThe design flaw in authentication model (authentication.rb) allows for interchangeable use of password and session tokens for user authentication As old tokens are not revoked upon password reset, an attacker who has obtained a valid session token can continue to authenticate and change the account’s password even after the victim resets it, thereby maintaining persistent control over the compromised account. PoC
ImpactPersistence of an attacker who obtained valid session token and preventing legitimate users from account access Affected versions
5.0.10
5.0.11
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.10.0
5.10.1
5.11.0
5.11.1
+ 71 more Show less
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.2.0
5.20.0
5.3.0
5.4.0
5.4.1
5.4.2
5.4.3.pre.beta0
5.5.0
5.5.0.pre.beta0
5.5.1
5.5.2
5.5.2.pre.beta0
5.6.0
5.6.1
5.7.0
5.7.2
5.8.0
5.8.1
5.9.0
5.9.1
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
7.0.0
7.0.0.pre.rc1
7.0.0.pre.rc2
7.0.0.pre.rc3
7.0.1
7.1.0
7.1.1
7.2.0
7.2.1
7.3.0
Fixed in
6.10.5
7.0.0-rc3
References
Updated Sep 10, 2026 · Source: OSV.dev |
7.0.0.pre.rc1
pre
Dependencies (61)
+ 53 more
Changelog
Compare changes
|
|
6.10.4
patch
5 CVEs
CVE-2026-42088
GHSA-2wvh-87g2-89hr
PYSEC-2026-2245
Apr 23, 2026
OpenC3 COSMOS: Permissions Bypass Provides User Access to Unassigned Administrative Actions via Script Runner Tool
9.6
/ 10
Critical
Network
Low
Low
None
Changed
High
High
None
Vulnerability Type: Execution with Unnecessary Privileges Attack type: Authenticated remote Impact: Data disclosure/manipulation, privilege escalation Affected components: The following docker images: • Openc3inc/openc3-COSMOS-script-runner-api The Script Runner widget allows users to execute Python and Ruby scripts directly from the openc3-COSMOS-script-runner-api container. Because all the docker containers share a network, users can execute specially crafted scripts to bypass the API permissions check and perform administrative actions, including reading and modifying data inside the Redis database, which can be used to read secrets and change COSMOS settings, as well as read and write to the buckets service, which holds configuration, log, and plugin files. These actions are normally only available from the Admin Console or with administrative privileges. Any user with permission to create and run scripts can connect to any service in the docker network. Figure 1: Environment variables, including Redis credentials, found in the Script Runner container A Ruby script is used to expose the Redis username, password, hostname, and port. These credentials might also be found from the source code or through a brute-force attack. Figure 2: A Python script is used to add data to Redis and retrieve the new data
A Python script is then used to create a new entry in the Redis database called Figure 3: The new data found in the Redis database
The new entry was successfully added to the Redis database, as is confirmed by using Figure 4: Uploading file to change the plugin store URL setting Figure 5: The URL file was successfully changed Steps To Reproduce
Recommendations• Limit the permissions of the script runner API to prevent lower level users from performing administrative actions Affected versions
5.0.10
5.0.11
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.10.0
5.10.1
5.11.0
5.11.1
+ 63 more Show less
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.2.0
5.20.0
5.3.0
5.4.0
5.4.1
5.4.2
5.4.3.pre.beta0
5.5.0
5.5.0.pre.beta0
5.5.1
5.5.2
5.5.2.pre.beta0
5.6.0
5.6.1
5.7.0
5.7.2
5.8.0
5.8.1
5.9.0
5.9.1
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.10.5
6.10.6
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
Fixed in
7.0.0-rc3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-42087
GHSA-v529-vhwc-wfc5
PYSEC-2026-2244
Apr 23, 2026
OpenC3 COSMOS has SQL Injection in QuestDB Time-Series Database
9.6
/ 10
Critical
Network
Low
Low
None
Changed
High
High
None
Vulnerability Type: CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Attack type: Authenticated remote Impact: Telemetry data disclosure and deletion Affected components: openc3-tsdb (QuestDB) A SQL injection vulnerability exists in the Time-Series Database (TSDB) component of COSMOS. The Figure 1: Source code vulnerable to SQL injection
Additionally, the Figure 2: Source code showing the required permissions for the Figure 3: A normal request to the Figure 4: The request and response after sending the SQL injection payload This payload can be modified to executes SQL commands in the TSDB. Figure 5: SQL injection used to execute arbitrary SQL command The user can then delete all the historical data in the database: Figure 6: Example payload dropping the tables Steps to Reproduce
Recommendations• Sanitize all user-supplied input before executing it • Use prepared statements with parameterized queries when executing SQL statements Affected versions
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.10.5
6.10.6
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
+ 1 more Show less
6.9.2
Fixed in
7.0.0-rc3
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-42086
GHSA-ffq5-qpvf-xq7x
PYSEC-2026-105
Apr 22, 2026
OpenC3 COSMOS is Vulnerable to Self-XSS Through the Command Sender
4.6
/ 10
Medium
Network
Low
Low
Required
Unchanged
Low
Low
None
SummaryThe Command Sender UI uses an unsafe DetailsThe unsafe PoC
Below example uses ImpactLocal JavaScript execution in the user's browser Affected versions
5.0.10
5.0.11
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.10.0
5.10.1
5.11.0
5.11.1
+ 66 more Show less
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.2.0
5.20.0
5.3.0
5.4.0
5.4.1
5.4.2
5.4.3.pre.beta0
5.5.0
5.5.0.pre.beta0
5.5.1
5.5.2
5.5.2.pre.beta0
5.6.0
5.6.1
5.7.0
5.7.2
5.8.0
5.8.1
5.9.0
5.9.1
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.10.5
6.10.6
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
7.0.0.pre.rc1
7.0.0.pre.rc2
7.0.0.pre.rc3
Fixed in
7.0.0
References
Updated May 29, 2026 · Source: OSV.dev
CVE-2026-42085
GHSA-4jvx-93h3-f45h
PYSEC-2026-2243
Apr 22, 2026
OpenC3 COSMOS allows arbitrary writes to plugins directory via path-traversed config filenames
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
None
SummaryOpenC3 COSMOS contains a design flaw in the DetailsIn function PoC
ImpactModifying the data of other plugins Affected versions
5.0.10
5.0.11
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.10.0
5.10.1
5.11.0
5.11.1
+ 71 more Show less
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.2.0
5.20.0
5.3.0
5.4.0
5.4.1
5.4.2
5.4.3.pre.beta0
5.5.0
5.5.0.pre.beta0
5.5.1
5.5.2
5.5.2.pre.beta0
5.6.0
5.6.1
5.7.0
5.7.2
5.8.0
5.8.1
5.9.0
5.9.1
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
7.0.0
7.0.0.pre.rc1
7.0.0.pre.rc2
7.0.0.pre.rc3
7.0.1
7.1.0
7.1.1
7.2.0
7.2.1
7.3.0
Fixed in
6.10.5
7.0.0-rc3
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-42084
GHSA-wgx6-g857-jjf7
PYSEC-2026-2242
Apr 22, 2026
OpenC3 COSMOS: Hijacked session token can be used to reset password for persistence
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
SummaryThe OpenC3 password change functionality allows a user to change their password without providing the old password, by accepting a valid session token instead. In assumed breach scenarios, this behaviour can be exploited by an attacker who has already obtained a valid session token, to gain persistence in hijacked account (including admin) and prevent legitimate users from accessing the account. DetailsThe design flaw in authentication model (authentication.rb) allows for interchangeable use of password and session tokens for user authentication As old tokens are not revoked upon password reset, an attacker who has obtained a valid session token can continue to authenticate and change the account’s password even after the victim resets it, thereby maintaining persistent control over the compromised account. PoC
ImpactPersistence of an attacker who obtained valid session token and preventing legitimate users from account access Affected versions
5.0.10
5.0.11
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.10.0
5.10.1
5.11.0
5.11.1
+ 71 more Show less
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.2.0
5.20.0
5.3.0
5.4.0
5.4.1
5.4.2
5.4.3.pre.beta0
5.5.0
5.5.0.pre.beta0
5.5.1
5.5.2
5.5.2.pre.beta0
5.6.0
5.6.1
5.7.0
5.7.2
5.8.0
5.8.1
5.9.0
5.9.1
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
7.0.0
7.0.0.pre.rc1
7.0.0.pre.rc2
7.0.0.pre.rc3
7.0.1
7.1.0
7.1.1
7.2.0
7.2.1
7.3.0
Fixed in
6.10.5
7.0.0-rc3
References
Updated Sep 10, 2026 · Source: OSV.dev |
6.10.4
patch
Dependencies (59)
+ 51 more
Changelog
Compare changes
|
|
6.10.3
patch
5 CVEs
CVE-2026-42088
GHSA-2wvh-87g2-89hr
PYSEC-2026-2245
Apr 23, 2026
OpenC3 COSMOS: Permissions Bypass Provides User Access to Unassigned Administrative Actions via Script Runner Tool
9.6
/ 10
Critical
Network
Low
Low
None
Changed
High
High
None
Vulnerability Type: Execution with Unnecessary Privileges Attack type: Authenticated remote Impact: Data disclosure/manipulation, privilege escalation Affected components: The following docker images: • Openc3inc/openc3-COSMOS-script-runner-api The Script Runner widget allows users to execute Python and Ruby scripts directly from the openc3-COSMOS-script-runner-api container. Because all the docker containers share a network, users can execute specially crafted scripts to bypass the API permissions check and perform administrative actions, including reading and modifying data inside the Redis database, which can be used to read secrets and change COSMOS settings, as well as read and write to the buckets service, which holds configuration, log, and plugin files. These actions are normally only available from the Admin Console or with administrative privileges. Any user with permission to create and run scripts can connect to any service in the docker network. Figure 1: Environment variables, including Redis credentials, found in the Script Runner container A Ruby script is used to expose the Redis username, password, hostname, and port. These credentials might also be found from the source code or through a brute-force attack. Figure 2: A Python script is used to add data to Redis and retrieve the new data
A Python script is then used to create a new entry in the Redis database called Figure 3: The new data found in the Redis database
The new entry was successfully added to the Redis database, as is confirmed by using Figure 4: Uploading file to change the plugin store URL setting Figure 5: The URL file was successfully changed Steps To Reproduce
Recommendations• Limit the permissions of the script runner API to prevent lower level users from performing administrative actions Affected versions
5.0.10
5.0.11
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.10.0
5.10.1
5.11.0
5.11.1
+ 63 more Show less
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.2.0
5.20.0
5.3.0
5.4.0
5.4.1
5.4.2
5.4.3.pre.beta0
5.5.0
5.5.0.pre.beta0
5.5.1
5.5.2
5.5.2.pre.beta0
5.6.0
5.6.1
5.7.0
5.7.2
5.8.0
5.8.1
5.9.0
5.9.1
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.10.5
6.10.6
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
Fixed in
7.0.0-rc3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-42087
GHSA-v529-vhwc-wfc5
PYSEC-2026-2244
Apr 23, 2026
OpenC3 COSMOS has SQL Injection in QuestDB Time-Series Database
9.6
/ 10
Critical
Network
Low
Low
None
Changed
High
High
None
Vulnerability Type: CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Attack type: Authenticated remote Impact: Telemetry data disclosure and deletion Affected components: openc3-tsdb (QuestDB) A SQL injection vulnerability exists in the Time-Series Database (TSDB) component of COSMOS. The Figure 1: Source code vulnerable to SQL injection
Additionally, the Figure 2: Source code showing the required permissions for the Figure 3: A normal request to the Figure 4: The request and response after sending the SQL injection payload This payload can be modified to executes SQL commands in the TSDB. Figure 5: SQL injection used to execute arbitrary SQL command The user can then delete all the historical data in the database: Figure 6: Example payload dropping the tables Steps to Reproduce
Recommendations• Sanitize all user-supplied input before executing it • Use prepared statements with parameterized queries when executing SQL statements Affected versions
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.10.5
6.10.6
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
+ 1 more Show less
6.9.2
Fixed in
7.0.0-rc3
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-42086
GHSA-ffq5-qpvf-xq7x
PYSEC-2026-105
Apr 22, 2026
OpenC3 COSMOS is Vulnerable to Self-XSS Through the Command Sender
4.6
/ 10
Medium
Network
Low
Low
Required
Unchanged
Low
Low
None
SummaryThe Command Sender UI uses an unsafe DetailsThe unsafe PoC
Below example uses ImpactLocal JavaScript execution in the user's browser Affected versions
5.0.10
5.0.11
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.10.0
5.10.1
5.11.0
5.11.1
+ 66 more Show less
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.2.0
5.20.0
5.3.0
5.4.0
5.4.1
5.4.2
5.4.3.pre.beta0
5.5.0
5.5.0.pre.beta0
5.5.1
5.5.2
5.5.2.pre.beta0
5.6.0
5.6.1
5.7.0
5.7.2
5.8.0
5.8.1
5.9.0
5.9.1
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.10.5
6.10.6
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
7.0.0.pre.rc1
7.0.0.pre.rc2
7.0.0.pre.rc3
Fixed in
7.0.0
References
Updated May 29, 2026 · Source: OSV.dev
CVE-2026-42085
GHSA-4jvx-93h3-f45h
PYSEC-2026-2243
Apr 22, 2026
OpenC3 COSMOS allows arbitrary writes to plugins directory via path-traversed config filenames
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
None
SummaryOpenC3 COSMOS contains a design flaw in the DetailsIn function PoC
ImpactModifying the data of other plugins Affected versions
5.0.10
5.0.11
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.10.0
5.10.1
5.11.0
5.11.1
+ 71 more Show less
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.2.0
5.20.0
5.3.0
5.4.0
5.4.1
5.4.2
5.4.3.pre.beta0
5.5.0
5.5.0.pre.beta0
5.5.1
5.5.2
5.5.2.pre.beta0
5.6.0
5.6.1
5.7.0
5.7.2
5.8.0
5.8.1
5.9.0
5.9.1
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
7.0.0
7.0.0.pre.rc1
7.0.0.pre.rc2
7.0.0.pre.rc3
7.0.1
7.1.0
7.1.1
7.2.0
7.2.1
7.3.0
Fixed in
6.10.5
7.0.0-rc3
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-42084
GHSA-wgx6-g857-jjf7
PYSEC-2026-2242
Apr 22, 2026
OpenC3 COSMOS: Hijacked session token can be used to reset password for persistence
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
SummaryThe OpenC3 password change functionality allows a user to change their password without providing the old password, by accepting a valid session token instead. In assumed breach scenarios, this behaviour can be exploited by an attacker who has already obtained a valid session token, to gain persistence in hijacked account (including admin) and prevent legitimate users from accessing the account. DetailsThe design flaw in authentication model (authentication.rb) allows for interchangeable use of password and session tokens for user authentication As old tokens are not revoked upon password reset, an attacker who has obtained a valid session token can continue to authenticate and change the account’s password even after the victim resets it, thereby maintaining persistent control over the compromised account. PoC
ImpactPersistence of an attacker who obtained valid session token and preventing legitimate users from account access Affected versions
5.0.10
5.0.11
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.10.0
5.10.1
5.11.0
5.11.1
+ 71 more Show less
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.2.0
5.20.0
5.3.0
5.4.0
5.4.1
5.4.2
5.4.3.pre.beta0
5.5.0
5.5.0.pre.beta0
5.5.1
5.5.2
5.5.2.pre.beta0
5.6.0
5.6.1
5.7.0
5.7.2
5.8.0
5.8.1
5.9.0
5.9.1
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
7.0.0
7.0.0.pre.rc1
7.0.0.pre.rc2
7.0.0.pre.rc3
7.0.1
7.1.0
7.1.1
7.2.0
7.2.1
7.3.0
Fixed in
6.10.5
7.0.0-rc3
References
Updated Sep 10, 2026 · Source: OSV.dev |
6.10.3
patch
Dependencies (59)
+ 51 more
Changelog
Compare changes
|
|
6.10.2
patch
5 CVEs
CVE-2026-42088
GHSA-2wvh-87g2-89hr
PYSEC-2026-2245
Apr 23, 2026
OpenC3 COSMOS: Permissions Bypass Provides User Access to Unassigned Administrative Actions via Script Runner Tool
9.6
/ 10
Critical
Network
Low
Low
None
Changed
High
High
None
Vulnerability Type: Execution with Unnecessary Privileges Attack type: Authenticated remote Impact: Data disclosure/manipulation, privilege escalation Affected components: The following docker images: • Openc3inc/openc3-COSMOS-script-runner-api The Script Runner widget allows users to execute Python and Ruby scripts directly from the openc3-COSMOS-script-runner-api container. Because all the docker containers share a network, users can execute specially crafted scripts to bypass the API permissions check and perform administrative actions, including reading and modifying data inside the Redis database, which can be used to read secrets and change COSMOS settings, as well as read and write to the buckets service, which holds configuration, log, and plugin files. These actions are normally only available from the Admin Console or with administrative privileges. Any user with permission to create and run scripts can connect to any service in the docker network. Figure 1: Environment variables, including Redis credentials, found in the Script Runner container A Ruby script is used to expose the Redis username, password, hostname, and port. These credentials might also be found from the source code or through a brute-force attack. Figure 2: A Python script is used to add data to Redis and retrieve the new data
A Python script is then used to create a new entry in the Redis database called Figure 3: The new data found in the Redis database
The new entry was successfully added to the Redis database, as is confirmed by using Figure 4: Uploading file to change the plugin store URL setting Figure 5: The URL file was successfully changed Steps To Reproduce
Recommendations• Limit the permissions of the script runner API to prevent lower level users from performing administrative actions Affected versions
5.0.10
5.0.11
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.10.0
5.10.1
5.11.0
5.11.1
+ 63 more Show less
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.2.0
5.20.0
5.3.0
5.4.0
5.4.1
5.4.2
5.4.3.pre.beta0
5.5.0
5.5.0.pre.beta0
5.5.1
5.5.2
5.5.2.pre.beta0
5.6.0
5.6.1
5.7.0
5.7.2
5.8.0
5.8.1
5.9.0
5.9.1
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.10.5
6.10.6
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
Fixed in
7.0.0-rc3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-42087
GHSA-v529-vhwc-wfc5
PYSEC-2026-2244
Apr 23, 2026
OpenC3 COSMOS has SQL Injection in QuestDB Time-Series Database
9.6
/ 10
Critical
Network
Low
Low
None
Changed
High
High
None
Vulnerability Type: CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Attack type: Authenticated remote Impact: Telemetry data disclosure and deletion Affected components: openc3-tsdb (QuestDB) A SQL injection vulnerability exists in the Time-Series Database (TSDB) component of COSMOS. The Figure 1: Source code vulnerable to SQL injection
Additionally, the Figure 2: Source code showing the required permissions for the Figure 3: A normal request to the Figure 4: The request and response after sending the SQL injection payload This payload can be modified to executes SQL commands in the TSDB. Figure 5: SQL injection used to execute arbitrary SQL command The user can then delete all the historical data in the database: Figure 6: Example payload dropping the tables Steps to Reproduce
Recommendations• Sanitize all user-supplied input before executing it • Use prepared statements with parameterized queries when executing SQL statements Affected versions
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.10.5
6.10.6
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
+ 1 more Show less
6.9.2
Fixed in
7.0.0-rc3
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-42086
GHSA-ffq5-qpvf-xq7x
PYSEC-2026-105
Apr 22, 2026
OpenC3 COSMOS is Vulnerable to Self-XSS Through the Command Sender
4.6
/ 10
Medium
Network
Low
Low
Required
Unchanged
Low
Low
None
SummaryThe Command Sender UI uses an unsafe DetailsThe unsafe PoC
Below example uses ImpactLocal JavaScript execution in the user's browser Affected versions
5.0.10
5.0.11
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.10.0
5.10.1
5.11.0
5.11.1
+ 66 more Show less
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.2.0
5.20.0
5.3.0
5.4.0
5.4.1
5.4.2
5.4.3.pre.beta0
5.5.0
5.5.0.pre.beta0
5.5.1
5.5.2
5.5.2.pre.beta0
5.6.0
5.6.1
5.7.0
5.7.2
5.8.0
5.8.1
5.9.0
5.9.1
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.10.5
6.10.6
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
7.0.0.pre.rc1
7.0.0.pre.rc2
7.0.0.pre.rc3
Fixed in
7.0.0
References
Updated May 29, 2026 · Source: OSV.dev
CVE-2026-42085
GHSA-4jvx-93h3-f45h
PYSEC-2026-2243
Apr 22, 2026
OpenC3 COSMOS allows arbitrary writes to plugins directory via path-traversed config filenames
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
None
SummaryOpenC3 COSMOS contains a design flaw in the DetailsIn function PoC
ImpactModifying the data of other plugins Affected versions
5.0.10
5.0.11
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.10.0
5.10.1
5.11.0
5.11.1
+ 71 more Show less
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.2.0
5.20.0
5.3.0
5.4.0
5.4.1
5.4.2
5.4.3.pre.beta0
5.5.0
5.5.0.pre.beta0
5.5.1
5.5.2
5.5.2.pre.beta0
5.6.0
5.6.1
5.7.0
5.7.2
5.8.0
5.8.1
5.9.0
5.9.1
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
7.0.0
7.0.0.pre.rc1
7.0.0.pre.rc2
7.0.0.pre.rc3
7.0.1
7.1.0
7.1.1
7.2.0
7.2.1
7.3.0
Fixed in
6.10.5
7.0.0-rc3
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-42084
GHSA-wgx6-g857-jjf7
PYSEC-2026-2242
Apr 22, 2026
OpenC3 COSMOS: Hijacked session token can be used to reset password for persistence
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
SummaryThe OpenC3 password change functionality allows a user to change their password without providing the old password, by accepting a valid session token instead. In assumed breach scenarios, this behaviour can be exploited by an attacker who has already obtained a valid session token, to gain persistence in hijacked account (including admin) and prevent legitimate users from accessing the account. DetailsThe design flaw in authentication model (authentication.rb) allows for interchangeable use of password and session tokens for user authentication As old tokens are not revoked upon password reset, an attacker who has obtained a valid session token can continue to authenticate and change the account’s password even after the victim resets it, thereby maintaining persistent control over the compromised account. PoC
ImpactPersistence of an attacker who obtained valid session token and preventing legitimate users from account access Affected versions
5.0.10
5.0.11
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.10.0
5.10.1
5.11.0
5.11.1
+ 71 more Show less
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.2.0
5.20.0
5.3.0
5.4.0
5.4.1
5.4.2
5.4.3.pre.beta0
5.5.0
5.5.0.pre.beta0
5.5.1
5.5.2
5.5.2.pre.beta0
5.6.0
5.6.1
5.7.0
5.7.2
5.8.0
5.8.1
5.9.0
5.9.1
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
7.0.0
7.0.0.pre.rc1
7.0.0.pre.rc2
7.0.0.pre.rc3
7.0.1
7.1.0
7.1.1
7.2.0
7.2.1
7.3.0
Fixed in
6.10.5
7.0.0-rc3
References
Updated Sep 10, 2026 · Source: OSV.dev |
6.10.2
patch
Dependencies (58)
+ 50 more
Changelog
Compare changes
|
|
6.10.1
patch
6 CVEs
CVE-2026-42088
GHSA-2wvh-87g2-89hr
PYSEC-2026-2245
Apr 23, 2026
OpenC3 COSMOS: Permissions Bypass Provides User Access to Unassigned Administrative Actions via Script Runner Tool
9.6
/ 10
Critical
Network
Low
Low
None
Changed
High
High
None
Vulnerability Type: Execution with Unnecessary Privileges Attack type: Authenticated remote Impact: Data disclosure/manipulation, privilege escalation Affected components: The following docker images: • Openc3inc/openc3-COSMOS-script-runner-api The Script Runner widget allows users to execute Python and Ruby scripts directly from the openc3-COSMOS-script-runner-api container. Because all the docker containers share a network, users can execute specially crafted scripts to bypass the API permissions check and perform administrative actions, including reading and modifying data inside the Redis database, which can be used to read secrets and change COSMOS settings, as well as read and write to the buckets service, which holds configuration, log, and plugin files. These actions are normally only available from the Admin Console or with administrative privileges. Any user with permission to create and run scripts can connect to any service in the docker network. Figure 1: Environment variables, including Redis credentials, found in the Script Runner container A Ruby script is used to expose the Redis username, password, hostname, and port. These credentials might also be found from the source code or through a brute-force attack. Figure 2: A Python script is used to add data to Redis and retrieve the new data
A Python script is then used to create a new entry in the Redis database called Figure 3: The new data found in the Redis database
The new entry was successfully added to the Redis database, as is confirmed by using Figure 4: Uploading file to change the plugin store URL setting Figure 5: The URL file was successfully changed Steps To Reproduce
Recommendations• Limit the permissions of the script runner API to prevent lower level users from performing administrative actions Affected versions
5.0.10
5.0.11
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.10.0
5.10.1
5.11.0
5.11.1
+ 63 more Show less
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.2.0
5.20.0
5.3.0
5.4.0
5.4.1
5.4.2
5.4.3.pre.beta0
5.5.0
5.5.0.pre.beta0
5.5.1
5.5.2
5.5.2.pre.beta0
5.6.0
5.6.1
5.7.0
5.7.2
5.8.0
5.8.1
5.9.0
5.9.1
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.10.5
6.10.6
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
Fixed in
7.0.0-rc3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-42087
GHSA-v529-vhwc-wfc5
PYSEC-2026-2244
Apr 23, 2026
OpenC3 COSMOS has SQL Injection in QuestDB Time-Series Database
9.6
/ 10
Critical
Network
Low
Low
None
Changed
High
High
None
Vulnerability Type: CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Attack type: Authenticated remote Impact: Telemetry data disclosure and deletion Affected components: openc3-tsdb (QuestDB) A SQL injection vulnerability exists in the Time-Series Database (TSDB) component of COSMOS. The Figure 1: Source code vulnerable to SQL injection
Additionally, the Figure 2: Source code showing the required permissions for the Figure 3: A normal request to the Figure 4: The request and response after sending the SQL injection payload This payload can be modified to executes SQL commands in the TSDB. Figure 5: SQL injection used to execute arbitrary SQL command The user can then delete all the historical data in the database: Figure 6: Example payload dropping the tables Steps to Reproduce
Recommendations• Sanitize all user-supplied input before executing it • Use prepared statements with parameterized queries when executing SQL statements Affected versions
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.10.5
6.10.6
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
+ 1 more Show less
6.9.2
Fixed in
7.0.0-rc3
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-42086
GHSA-ffq5-qpvf-xq7x
PYSEC-2026-105
Apr 22, 2026
OpenC3 COSMOS is Vulnerable to Self-XSS Through the Command Sender
4.6
/ 10
Medium
Network
Low
Low
Required
Unchanged
Low
Low
None
SummaryThe Command Sender UI uses an unsafe DetailsThe unsafe PoC
Below example uses ImpactLocal JavaScript execution in the user's browser Affected versions
5.0.10
5.0.11
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.10.0
5.10.1
5.11.0
5.11.1
+ 66 more Show less
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.2.0
5.20.0
5.3.0
5.4.0
5.4.1
5.4.2
5.4.3.pre.beta0
5.5.0
5.5.0.pre.beta0
5.5.1
5.5.2
5.5.2.pre.beta0
5.6.0
5.6.1
5.7.0
5.7.2
5.8.0
5.8.1
5.9.0
5.9.1
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.10.5
6.10.6
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
7.0.0.pre.rc1
7.0.0.pre.rc2
7.0.0.pre.rc3
Fixed in
7.0.0
References
Updated May 29, 2026 · Source: OSV.dev
CVE-2026-42085
GHSA-4jvx-93h3-f45h
PYSEC-2026-2243
Apr 22, 2026
OpenC3 COSMOS allows arbitrary writes to plugins directory via path-traversed config filenames
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
None
SummaryOpenC3 COSMOS contains a design flaw in the DetailsIn function PoC
ImpactModifying the data of other plugins Affected versions
5.0.10
5.0.11
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.10.0
5.10.1
5.11.0
5.11.1
+ 71 more Show less
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.2.0
5.20.0
5.3.0
5.4.0
5.4.1
5.4.2
5.4.3.pre.beta0
5.5.0
5.5.0.pre.beta0
5.5.1
5.5.2
5.5.2.pre.beta0
5.6.0
5.6.1
5.7.0
5.7.2
5.8.0
5.8.1
5.9.0
5.9.1
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
7.0.0
7.0.0.pre.rc1
7.0.0.pre.rc2
7.0.0.pre.rc3
7.0.1
7.1.0
7.1.1
7.2.0
7.2.1
7.3.0
Fixed in
6.10.5
7.0.0-rc3
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-42084
GHSA-wgx6-g857-jjf7
PYSEC-2026-2242
Apr 22, 2026
OpenC3 COSMOS: Hijacked session token can be used to reset password for persistence
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
SummaryThe OpenC3 password change functionality allows a user to change their password without providing the old password, by accepting a valid session token instead. In assumed breach scenarios, this behaviour can be exploited by an attacker who has already obtained a valid session token, to gain persistence in hijacked account (including admin) and prevent legitimate users from accessing the account. DetailsThe design flaw in authentication model (authentication.rb) allows for interchangeable use of password and session tokens for user authentication As old tokens are not revoked upon password reset, an attacker who has obtained a valid session token can continue to authenticate and change the account’s password even after the victim resets it, thereby maintaining persistent control over the compromised account. PoC
ImpactPersistence of an attacker who obtained valid session token and preventing legitimate users from account access Affected versions
5.0.10
5.0.11
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.10.0
5.10.1
5.11.0
5.11.1
+ 71 more Show less
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.2.0
5.20.0
5.3.0
5.4.0
5.4.1
5.4.2
5.4.3.pre.beta0
5.5.0
5.5.0.pre.beta0
5.5.1
5.5.2
5.5.2.pre.beta0
5.6.0
5.6.1
5.7.0
5.7.2
5.8.0
5.8.1
5.9.0
5.9.1
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
7.0.0
7.0.0.pre.rc1
7.0.0.pre.rc2
7.0.0.pre.rc3
7.0.1
7.1.0
7.1.1
7.2.0
7.2.1
7.3.0
Fixed in
6.10.5
7.0.0-rc3
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2025-68271
GHSA-w757-4qv9-mghp
Jan 13, 2026
openc3-api Vulnerable to Unauthenticated Remote Code Execution
10.0
/ 10
Critical
Network
Low
None
None
Changed
High
High
High
SummaryOpenC3 COSMOS contains a critical remote code execution vulnerability reachable through the JSON-RPC API. When a JSON-RPC request uses the string form of certain APIs, attacker-controlled parameter text is parsed into values using String#convert_to_value. For array-like inputs, convert_to_value executes eval(). Because the cmd code path parses the command string before calling authorize(), an unauthenticated attacker can trigger Ruby code execution even though the request ultimately fails authorization (401). Affected versions
5.0.10
5.0.11
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.10.0
5.10.1
5.11.0
5.11.1
+ 58 more Show less
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.2.0
5.20.0
5.3.0
5.4.0
5.4.1
5.4.2
5.4.3.pre.beta0
5.5.0
5.5.0.pre.beta0
5.5.1
5.5.2
5.5.2.pre.beta0
5.6.0
5.6.1
5.7.0
5.7.2
5.8.0
5.8.1
5.9.0
5.9.1
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
Fixed in
6.10.2
References
Updated Feb 03, 2026 · Source: OSV.dev |
6.10.1
patch
Dependencies (59)
+ 51 more
Changelog
Compare changes
|
|
6.10.0
minor
6 CVEs
CVE-2026-42088
GHSA-2wvh-87g2-89hr
PYSEC-2026-2245
Apr 23, 2026
OpenC3 COSMOS: Permissions Bypass Provides User Access to Unassigned Administrative Actions via Script Runner Tool
9.6
/ 10
Critical
Network
Low
Low
None
Changed
High
High
None
Vulnerability Type: Execution with Unnecessary Privileges Attack type: Authenticated remote Impact: Data disclosure/manipulation, privilege escalation Affected components: The following docker images: • Openc3inc/openc3-COSMOS-script-runner-api The Script Runner widget allows users to execute Python and Ruby scripts directly from the openc3-COSMOS-script-runner-api container. Because all the docker containers share a network, users can execute specially crafted scripts to bypass the API permissions check and perform administrative actions, including reading and modifying data inside the Redis database, which can be used to read secrets and change COSMOS settings, as well as read and write to the buckets service, which holds configuration, log, and plugin files. These actions are normally only available from the Admin Console or with administrative privileges. Any user with permission to create and run scripts can connect to any service in the docker network. Figure 1: Environment variables, including Redis credentials, found in the Script Runner container A Ruby script is used to expose the Redis username, password, hostname, and port. These credentials might also be found from the source code or through a brute-force attack. Figure 2: A Python script is used to add data to Redis and retrieve the new data
A Python script is then used to create a new entry in the Redis database called Figure 3: The new data found in the Redis database
The new entry was successfully added to the Redis database, as is confirmed by using Figure 4: Uploading file to change the plugin store URL setting Figure 5: The URL file was successfully changed Steps To Reproduce
Recommendations• Limit the permissions of the script runner API to prevent lower level users from performing administrative actions Affected versions
5.0.10
5.0.11
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.10.0
5.10.1
5.11.0
5.11.1
+ 63 more Show less
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.2.0
5.20.0
5.3.0
5.4.0
5.4.1
5.4.2
5.4.3.pre.beta0
5.5.0
5.5.0.pre.beta0
5.5.1
5.5.2
5.5.2.pre.beta0
5.6.0
5.6.1
5.7.0
5.7.2
5.8.0
5.8.1
5.9.0
5.9.1
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.10.5
6.10.6
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
Fixed in
7.0.0-rc3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-42087
GHSA-v529-vhwc-wfc5
PYSEC-2026-2244
Apr 23, 2026
OpenC3 COSMOS has SQL Injection in QuestDB Time-Series Database
9.6
/ 10
Critical
Network
Low
Low
None
Changed
High
High
None
Vulnerability Type: CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Attack type: Authenticated remote Impact: Telemetry data disclosure and deletion Affected components: openc3-tsdb (QuestDB) A SQL injection vulnerability exists in the Time-Series Database (TSDB) component of COSMOS. The Figure 1: Source code vulnerable to SQL injection
Additionally, the Figure 2: Source code showing the required permissions for the Figure 3: A normal request to the Figure 4: The request and response after sending the SQL injection payload This payload can be modified to executes SQL commands in the TSDB. Figure 5: SQL injection used to execute arbitrary SQL command The user can then delete all the historical data in the database: Figure 6: Example payload dropping the tables Steps to Reproduce
Recommendations• Sanitize all user-supplied input before executing it • Use prepared statements with parameterized queries when executing SQL statements Affected versions
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.10.5
6.10.6
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
+ 1 more Show less
6.9.2
Fixed in
7.0.0-rc3
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-42086
GHSA-ffq5-qpvf-xq7x
PYSEC-2026-105
Apr 22, 2026
OpenC3 COSMOS is Vulnerable to Self-XSS Through the Command Sender
4.6
/ 10
Medium
Network
Low
Low
Required
Unchanged
Low
Low
None
SummaryThe Command Sender UI uses an unsafe DetailsThe unsafe PoC
Below example uses ImpactLocal JavaScript execution in the user's browser Affected versions
5.0.10
5.0.11
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.10.0
5.10.1
5.11.0
5.11.1
+ 66 more Show less
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.2.0
5.20.0
5.3.0
5.4.0
5.4.1
5.4.2
5.4.3.pre.beta0
5.5.0
5.5.0.pre.beta0
5.5.1
5.5.2
5.5.2.pre.beta0
5.6.0
5.6.1
5.7.0
5.7.2
5.8.0
5.8.1
5.9.0
5.9.1
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.10.5
6.10.6
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
7.0.0.pre.rc1
7.0.0.pre.rc2
7.0.0.pre.rc3
Fixed in
7.0.0
References
Updated May 29, 2026 · Source: OSV.dev
CVE-2026-42085
GHSA-4jvx-93h3-f45h
PYSEC-2026-2243
Apr 22, 2026
OpenC3 COSMOS allows arbitrary writes to plugins directory via path-traversed config filenames
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
None
SummaryOpenC3 COSMOS contains a design flaw in the DetailsIn function PoC
ImpactModifying the data of other plugins Affected versions
5.0.10
5.0.11
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.10.0
5.10.1
5.11.0
5.11.1
+ 71 more Show less
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.2.0
5.20.0
5.3.0
5.4.0
5.4.1
5.4.2
5.4.3.pre.beta0
5.5.0
5.5.0.pre.beta0
5.5.1
5.5.2
5.5.2.pre.beta0
5.6.0
5.6.1
5.7.0
5.7.2
5.8.0
5.8.1
5.9.0
5.9.1
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
7.0.0
7.0.0.pre.rc1
7.0.0.pre.rc2
7.0.0.pre.rc3
7.0.1
7.1.0
7.1.1
7.2.0
7.2.1
7.3.0
Fixed in
6.10.5
7.0.0-rc3
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-42084
GHSA-wgx6-g857-jjf7
PYSEC-2026-2242
Apr 22, 2026
OpenC3 COSMOS: Hijacked session token can be used to reset password for persistence
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
SummaryThe OpenC3 password change functionality allows a user to change their password without providing the old password, by accepting a valid session token instead. In assumed breach scenarios, this behaviour can be exploited by an attacker who has already obtained a valid session token, to gain persistence in hijacked account (including admin) and prevent legitimate users from accessing the account. DetailsThe design flaw in authentication model (authentication.rb) allows for interchangeable use of password and session tokens for user authentication As old tokens are not revoked upon password reset, an attacker who has obtained a valid session token can continue to authenticate and change the account’s password even after the victim resets it, thereby maintaining persistent control over the compromised account. PoC
ImpactPersistence of an attacker who obtained valid session token and preventing legitimate users from account access Affected versions
5.0.10
5.0.11
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.10.0
5.10.1
5.11.0
5.11.1
+ 71 more Show less
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.2.0
5.20.0
5.3.0
5.4.0
5.4.1
5.4.2
5.4.3.pre.beta0
5.5.0
5.5.0.pre.beta0
5.5.1
5.5.2
5.5.2.pre.beta0
5.6.0
5.6.1
5.7.0
5.7.2
5.8.0
5.8.1
5.9.0
5.9.1
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
7.0.0
7.0.0.pre.rc1
7.0.0.pre.rc2
7.0.0.pre.rc3
7.0.1
7.1.0
7.1.1
7.2.0
7.2.1
7.3.0
Fixed in
6.10.5
7.0.0-rc3
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2025-68271
GHSA-w757-4qv9-mghp
Jan 13, 2026
openc3-api Vulnerable to Unauthenticated Remote Code Execution
10.0
/ 10
Critical
Network
Low
None
None
Changed
High
High
High
SummaryOpenC3 COSMOS contains a critical remote code execution vulnerability reachable through the JSON-RPC API. When a JSON-RPC request uses the string form of certain APIs, attacker-controlled parameter text is parsed into values using String#convert_to_value. For array-like inputs, convert_to_value executes eval(). Because the cmd code path parses the command string before calling authorize(), an unauthenticated attacker can trigger Ruby code execution even though the request ultimately fails authorization (401). Affected versions
5.0.10
5.0.11
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.10.0
5.10.1
5.11.0
5.11.1
+ 58 more Show less
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.2.0
5.20.0
5.3.0
5.4.0
5.4.1
5.4.2
5.4.3.pre.beta0
5.5.0
5.5.0.pre.beta0
5.5.1
5.5.2
5.5.2.pre.beta0
5.6.0
5.6.1
5.7.0
5.7.2
5.8.0
5.8.1
5.9.0
5.9.1
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
Fixed in
6.10.2
References
Updated Feb 03, 2026 · Source: OSV.dev |
6.10.0
minor
Dependencies (59)
+ 51 more
Changelog
Compare changes
|
|
6.9.2
patch
6 CVEs
CVE-2026-42088
GHSA-2wvh-87g2-89hr
PYSEC-2026-2245
Apr 23, 2026
OpenC3 COSMOS: Permissions Bypass Provides User Access to Unassigned Administrative Actions via Script Runner Tool
9.6
/ 10
Critical
Network
Low
Low
None
Changed
High
High
None
Vulnerability Type: Execution with Unnecessary Privileges Attack type: Authenticated remote Impact: Data disclosure/manipulation, privilege escalation Affected components: The following docker images: • Openc3inc/openc3-COSMOS-script-runner-api The Script Runner widget allows users to execute Python and Ruby scripts directly from the openc3-COSMOS-script-runner-api container. Because all the docker containers share a network, users can execute specially crafted scripts to bypass the API permissions check and perform administrative actions, including reading and modifying data inside the Redis database, which can be used to read secrets and change COSMOS settings, as well as read and write to the buckets service, which holds configuration, log, and plugin files. These actions are normally only available from the Admin Console or with administrative privileges. Any user with permission to create and run scripts can connect to any service in the docker network. Figure 1: Environment variables, including Redis credentials, found in the Script Runner container A Ruby script is used to expose the Redis username, password, hostname, and port. These credentials might also be found from the source code or through a brute-force attack. Figure 2: A Python script is used to add data to Redis and retrieve the new data
A Python script is then used to create a new entry in the Redis database called Figure 3: The new data found in the Redis database
The new entry was successfully added to the Redis database, as is confirmed by using Figure 4: Uploading file to change the plugin store URL setting Figure 5: The URL file was successfully changed Steps To Reproduce
Recommendations• Limit the permissions of the script runner API to prevent lower level users from performing administrative actions Affected versions
5.0.10
5.0.11
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.10.0
5.10.1
5.11.0
5.11.1
+ 63 more Show less
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.2.0
5.20.0
5.3.0
5.4.0
5.4.1
5.4.2
5.4.3.pre.beta0
5.5.0
5.5.0.pre.beta0
5.5.1
5.5.2
5.5.2.pre.beta0
5.6.0
5.6.1
5.7.0
5.7.2
5.8.0
5.8.1
5.9.0
5.9.1
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.10.5
6.10.6
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
Fixed in
7.0.0-rc3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-42087
GHSA-v529-vhwc-wfc5
PYSEC-2026-2244
Apr 23, 2026
OpenC3 COSMOS has SQL Injection in QuestDB Time-Series Database
9.6
/ 10
Critical
Network
Low
Low
None
Changed
High
High
None
Vulnerability Type: CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Attack type: Authenticated remote Impact: Telemetry data disclosure and deletion Affected components: openc3-tsdb (QuestDB) A SQL injection vulnerability exists in the Time-Series Database (TSDB) component of COSMOS. The Figure 1: Source code vulnerable to SQL injection
Additionally, the Figure 2: Source code showing the required permissions for the Figure 3: A normal request to the Figure 4: The request and response after sending the SQL injection payload This payload can be modified to executes SQL commands in the TSDB. Figure 5: SQL injection used to execute arbitrary SQL command The user can then delete all the historical data in the database: Figure 6: Example payload dropping the tables Steps to Reproduce
Recommendations• Sanitize all user-supplied input before executing it • Use prepared statements with parameterized queries when executing SQL statements Affected versions
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.10.5
6.10.6
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
+ 1 more Show less
6.9.2
Fixed in
7.0.0-rc3
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-42086
GHSA-ffq5-qpvf-xq7x
PYSEC-2026-105
Apr 22, 2026
OpenC3 COSMOS is Vulnerable to Self-XSS Through the Command Sender
4.6
/ 10
Medium
Network
Low
Low
Required
Unchanged
Low
Low
None
SummaryThe Command Sender UI uses an unsafe DetailsThe unsafe PoC
Below example uses ImpactLocal JavaScript execution in the user's browser Affected versions
5.0.10
5.0.11
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.10.0
5.10.1
5.11.0
5.11.1
+ 66 more Show less
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.2.0
5.20.0
5.3.0
5.4.0
5.4.1
5.4.2
5.4.3.pre.beta0
5.5.0
5.5.0.pre.beta0
5.5.1
5.5.2
5.5.2.pre.beta0
5.6.0
5.6.1
5.7.0
5.7.2
5.8.0
5.8.1
5.9.0
5.9.1
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.10.5
6.10.6
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
7.0.0.pre.rc1
7.0.0.pre.rc2
7.0.0.pre.rc3
Fixed in
7.0.0
References
Updated May 29, 2026 · Source: OSV.dev
CVE-2026-42085
GHSA-4jvx-93h3-f45h
PYSEC-2026-2243
Apr 22, 2026
OpenC3 COSMOS allows arbitrary writes to plugins directory via path-traversed config filenames
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
None
SummaryOpenC3 COSMOS contains a design flaw in the DetailsIn function PoC
ImpactModifying the data of other plugins Affected versions
5.0.10
5.0.11
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.10.0
5.10.1
5.11.0
5.11.1
+ 71 more Show less
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.2.0
5.20.0
5.3.0
5.4.0
5.4.1
5.4.2
5.4.3.pre.beta0
5.5.0
5.5.0.pre.beta0
5.5.1
5.5.2
5.5.2.pre.beta0
5.6.0
5.6.1
5.7.0
5.7.2
5.8.0
5.8.1
5.9.0
5.9.1
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
7.0.0
7.0.0.pre.rc1
7.0.0.pre.rc2
7.0.0.pre.rc3
7.0.1
7.1.0
7.1.1
7.2.0
7.2.1
7.3.0
Fixed in
6.10.5
7.0.0-rc3
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-42084
GHSA-wgx6-g857-jjf7
PYSEC-2026-2242
Apr 22, 2026
OpenC3 COSMOS: Hijacked session token can be used to reset password for persistence
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
SummaryThe OpenC3 password change functionality allows a user to change their password without providing the old password, by accepting a valid session token instead. In assumed breach scenarios, this behaviour can be exploited by an attacker who has already obtained a valid session token, to gain persistence in hijacked account (including admin) and prevent legitimate users from accessing the account. DetailsThe design flaw in authentication model (authentication.rb) allows for interchangeable use of password and session tokens for user authentication As old tokens are not revoked upon password reset, an attacker who has obtained a valid session token can continue to authenticate and change the account’s password even after the victim resets it, thereby maintaining persistent control over the compromised account. PoC
ImpactPersistence of an attacker who obtained valid session token and preventing legitimate users from account access Affected versions
5.0.10
5.0.11
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.10.0
5.10.1
5.11.0
5.11.1
+ 71 more Show less
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.2.0
5.20.0
5.3.0
5.4.0
5.4.1
5.4.2
5.4.3.pre.beta0
5.5.0
5.5.0.pre.beta0
5.5.1
5.5.2
5.5.2.pre.beta0
5.6.0
5.6.1
5.7.0
5.7.2
5.8.0
5.8.1
5.9.0
5.9.1
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
7.0.0
7.0.0.pre.rc1
7.0.0.pre.rc2
7.0.0.pre.rc3
7.0.1
7.1.0
7.1.1
7.2.0
7.2.1
7.3.0
Fixed in
6.10.5
7.0.0-rc3
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2025-68271
GHSA-w757-4qv9-mghp
Jan 13, 2026
openc3-api Vulnerable to Unauthenticated Remote Code Execution
10.0
/ 10
Critical
Network
Low
None
None
Changed
High
High
High
SummaryOpenC3 COSMOS contains a critical remote code execution vulnerability reachable through the JSON-RPC API. When a JSON-RPC request uses the string form of certain APIs, attacker-controlled parameter text is parsed into values using String#convert_to_value. For array-like inputs, convert_to_value executes eval(). Because the cmd code path parses the command string before calling authorize(), an unauthenticated attacker can trigger Ruby code execution even though the request ultimately fails authorization (401). Affected versions
5.0.10
5.0.11
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.10.0
5.10.1
5.11.0
5.11.1
+ 58 more Show less
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.2.0
5.20.0
5.3.0
5.4.0
5.4.1
5.4.2
5.4.3.pre.beta0
5.5.0
5.5.0.pre.beta0
5.5.1
5.5.2
5.5.2.pre.beta0
5.6.0
5.6.1
5.7.0
5.7.2
5.8.0
5.8.1
5.9.0
5.9.1
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
Fixed in
6.10.2
References
Updated Feb 03, 2026 · Source: OSV.dev |
6.9.2
patch
Dependencies (59)
+ 51 more
Changelog
Compare changes
|
|
6.9.1
patch
6 CVEs
CVE-2026-42088
GHSA-2wvh-87g2-89hr
PYSEC-2026-2245
Apr 23, 2026
OpenC3 COSMOS: Permissions Bypass Provides User Access to Unassigned Administrative Actions via Script Runner Tool
9.6
/ 10
Critical
Network
Low
Low
None
Changed
High
High
None
Vulnerability Type: Execution with Unnecessary Privileges Attack type: Authenticated remote Impact: Data disclosure/manipulation, privilege escalation Affected components: The following docker images: • Openc3inc/openc3-COSMOS-script-runner-api The Script Runner widget allows users to execute Python and Ruby scripts directly from the openc3-COSMOS-script-runner-api container. Because all the docker containers share a network, users can execute specially crafted scripts to bypass the API permissions check and perform administrative actions, including reading and modifying data inside the Redis database, which can be used to read secrets and change COSMOS settings, as well as read and write to the buckets service, which holds configuration, log, and plugin files. These actions are normally only available from the Admin Console or with administrative privileges. Any user with permission to create and run scripts can connect to any service in the docker network. Figure 1: Environment variables, including Redis credentials, found in the Script Runner container A Ruby script is used to expose the Redis username, password, hostname, and port. These credentials might also be found from the source code or through a brute-force attack. Figure 2: A Python script is used to add data to Redis and retrieve the new data
A Python script is then used to create a new entry in the Redis database called Figure 3: The new data found in the Redis database
The new entry was successfully added to the Redis database, as is confirmed by using Figure 4: Uploading file to change the plugin store URL setting Figure 5: The URL file was successfully changed Steps To Reproduce
Recommendations• Limit the permissions of the script runner API to prevent lower level users from performing administrative actions Affected versions
5.0.10
5.0.11
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.10.0
5.10.1
5.11.0
5.11.1
+ 63 more Show less
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.2.0
5.20.0
5.3.0
5.4.0
5.4.1
5.4.2
5.4.3.pre.beta0
5.5.0
5.5.0.pre.beta0
5.5.1
5.5.2
5.5.2.pre.beta0
5.6.0
5.6.1
5.7.0
5.7.2
5.8.0
5.8.1
5.9.0
5.9.1
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.10.5
6.10.6
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
Fixed in
7.0.0-rc3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-42087
GHSA-v529-vhwc-wfc5
PYSEC-2026-2244
Apr 23, 2026
OpenC3 COSMOS has SQL Injection in QuestDB Time-Series Database
9.6
/ 10
Critical
Network
Low
Low
None
Changed
High
High
None
Vulnerability Type: CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Attack type: Authenticated remote Impact: Telemetry data disclosure and deletion Affected components: openc3-tsdb (QuestDB) A SQL injection vulnerability exists in the Time-Series Database (TSDB) component of COSMOS. The Figure 1: Source code vulnerable to SQL injection
Additionally, the Figure 2: Source code showing the required permissions for the Figure 3: A normal request to the Figure 4: The request and response after sending the SQL injection payload This payload can be modified to executes SQL commands in the TSDB. Figure 5: SQL injection used to execute arbitrary SQL command The user can then delete all the historical data in the database: Figure 6: Example payload dropping the tables Steps to Reproduce
Recommendations• Sanitize all user-supplied input before executing it • Use prepared statements with parameterized queries when executing SQL statements Affected versions
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.10.5
6.10.6
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
+ 1 more Show less
6.9.2
Fixed in
7.0.0-rc3
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-42086
GHSA-ffq5-qpvf-xq7x
PYSEC-2026-105
Apr 22, 2026
OpenC3 COSMOS is Vulnerable to Self-XSS Through the Command Sender
4.6
/ 10
Medium
Network
Low
Low
Required
Unchanged
Low
Low
None
SummaryThe Command Sender UI uses an unsafe DetailsThe unsafe PoC
Below example uses ImpactLocal JavaScript execution in the user's browser Affected versions
5.0.10
5.0.11
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.10.0
5.10.1
5.11.0
5.11.1
+ 66 more Show less
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.2.0
5.20.0
5.3.0
5.4.0
5.4.1
5.4.2
5.4.3.pre.beta0
5.5.0
5.5.0.pre.beta0
5.5.1
5.5.2
5.5.2.pre.beta0
5.6.0
5.6.1
5.7.0
5.7.2
5.8.0
5.8.1
5.9.0
5.9.1
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.10.5
6.10.6
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
7.0.0.pre.rc1
7.0.0.pre.rc2
7.0.0.pre.rc3
Fixed in
7.0.0
References
Updated May 29, 2026 · Source: OSV.dev
CVE-2026-42085
GHSA-4jvx-93h3-f45h
PYSEC-2026-2243
Apr 22, 2026
OpenC3 COSMOS allows arbitrary writes to plugins directory via path-traversed config filenames
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
None
SummaryOpenC3 COSMOS contains a design flaw in the DetailsIn function PoC
ImpactModifying the data of other plugins Affected versions
5.0.10
5.0.11
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.10.0
5.10.1
5.11.0
5.11.1
+ 71 more Show less
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.2.0
5.20.0
5.3.0
5.4.0
5.4.1
5.4.2
5.4.3.pre.beta0
5.5.0
5.5.0.pre.beta0
5.5.1
5.5.2
5.5.2.pre.beta0
5.6.0
5.6.1
5.7.0
5.7.2
5.8.0
5.8.1
5.9.0
5.9.1
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
7.0.0
7.0.0.pre.rc1
7.0.0.pre.rc2
7.0.0.pre.rc3
7.0.1
7.1.0
7.1.1
7.2.0
7.2.1
7.3.0
Fixed in
6.10.5
7.0.0-rc3
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-42084
GHSA-wgx6-g857-jjf7
PYSEC-2026-2242
Apr 22, 2026
OpenC3 COSMOS: Hijacked session token can be used to reset password for persistence
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
SummaryThe OpenC3 password change functionality allows a user to change their password without providing the old password, by accepting a valid session token instead. In assumed breach scenarios, this behaviour can be exploited by an attacker who has already obtained a valid session token, to gain persistence in hijacked account (including admin) and prevent legitimate users from accessing the account. DetailsThe design flaw in authentication model (authentication.rb) allows for interchangeable use of password and session tokens for user authentication As old tokens are not revoked upon password reset, an attacker who has obtained a valid session token can continue to authenticate and change the account’s password even after the victim resets it, thereby maintaining persistent control over the compromised account. PoC
ImpactPersistence of an attacker who obtained valid session token and preventing legitimate users from account access Affected versions
5.0.10
5.0.11
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.10.0
5.10.1
5.11.0
5.11.1
+ 71 more Show less
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.2.0
5.20.0
5.3.0
5.4.0
5.4.1
5.4.2
5.4.3.pre.beta0
5.5.0
5.5.0.pre.beta0
5.5.1
5.5.2
5.5.2.pre.beta0
5.6.0
5.6.1
5.7.0
5.7.2
5.8.0
5.8.1
5.9.0
5.9.1
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
7.0.0
7.0.0.pre.rc1
7.0.0.pre.rc2
7.0.0.pre.rc3
7.0.1
7.1.0
7.1.1
7.2.0
7.2.1
7.3.0
Fixed in
6.10.5
7.0.0-rc3
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2025-68271
GHSA-w757-4qv9-mghp
Jan 13, 2026
openc3-api Vulnerable to Unauthenticated Remote Code Execution
10.0
/ 10
Critical
Network
Low
None
None
Changed
High
High
High
SummaryOpenC3 COSMOS contains a critical remote code execution vulnerability reachable through the JSON-RPC API. When a JSON-RPC request uses the string form of certain APIs, attacker-controlled parameter text is parsed into values using String#convert_to_value. For array-like inputs, convert_to_value executes eval(). Because the cmd code path parses the command string before calling authorize(), an unauthenticated attacker can trigger Ruby code execution even though the request ultimately fails authorization (401). Affected versions
5.0.10
5.0.11
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.10.0
5.10.1
5.11.0
5.11.1
+ 58 more Show less
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.2.0
5.20.0
5.3.0
5.4.0
5.4.1
5.4.2
5.4.3.pre.beta0
5.5.0
5.5.0.pre.beta0
5.5.1
5.5.2
5.5.2.pre.beta0
5.6.0
5.6.1
5.7.0
5.7.2
5.8.0
5.8.1
5.9.0
5.9.1
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
Fixed in
6.10.2
References
Updated Feb 03, 2026 · Source: OSV.dev |
6.9.1
patch
Dependencies (59)
+ 51 more
Changelog
Compare changes
|
|
6.9.0
minor
6 CVEs
CVE-2026-42088
GHSA-2wvh-87g2-89hr
PYSEC-2026-2245
Apr 23, 2026
OpenC3 COSMOS: Permissions Bypass Provides User Access to Unassigned Administrative Actions via Script Runner Tool
9.6
/ 10
Critical
Network
Low
Low
None
Changed
High
High
None
Vulnerability Type: Execution with Unnecessary Privileges Attack type: Authenticated remote Impact: Data disclosure/manipulation, privilege escalation Affected components: The following docker images: • Openc3inc/openc3-COSMOS-script-runner-api The Script Runner widget allows users to execute Python and Ruby scripts directly from the openc3-COSMOS-script-runner-api container. Because all the docker containers share a network, users can execute specially crafted scripts to bypass the API permissions check and perform administrative actions, including reading and modifying data inside the Redis database, which can be used to read secrets and change COSMOS settings, as well as read and write to the buckets service, which holds configuration, log, and plugin files. These actions are normally only available from the Admin Console or with administrative privileges. Any user with permission to create and run scripts can connect to any service in the docker network. Figure 1: Environment variables, including Redis credentials, found in the Script Runner container A Ruby script is used to expose the Redis username, password, hostname, and port. These credentials might also be found from the source code or through a brute-force attack. Figure 2: A Python script is used to add data to Redis and retrieve the new data
A Python script is then used to create a new entry in the Redis database called Figure 3: The new data found in the Redis database
The new entry was successfully added to the Redis database, as is confirmed by using Figure 4: Uploading file to change the plugin store URL setting Figure 5: The URL file was successfully changed Steps To Reproduce
Recommendations• Limit the permissions of the script runner API to prevent lower level users from performing administrative actions Affected versions
5.0.10
5.0.11
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.10.0
5.10.1
5.11.0
5.11.1
+ 63 more Show less
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.2.0
5.20.0
5.3.0
5.4.0
5.4.1
5.4.2
5.4.3.pre.beta0
5.5.0
5.5.0.pre.beta0
5.5.1
5.5.2
5.5.2.pre.beta0
5.6.0
5.6.1
5.7.0
5.7.2
5.8.0
5.8.1
5.9.0
5.9.1
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.10.5
6.10.6
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
Fixed in
7.0.0-rc3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-42087
GHSA-v529-vhwc-wfc5
PYSEC-2026-2244
Apr 23, 2026
OpenC3 COSMOS has SQL Injection in QuestDB Time-Series Database
9.6
/ 10
Critical
Network
Low
Low
None
Changed
High
High
None
Vulnerability Type: CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Attack type: Authenticated remote Impact: Telemetry data disclosure and deletion Affected components: openc3-tsdb (QuestDB) A SQL injection vulnerability exists in the Time-Series Database (TSDB) component of COSMOS. The Figure 1: Source code vulnerable to SQL injection
Additionally, the Figure 2: Source code showing the required permissions for the Figure 3: A normal request to the Figure 4: The request and response after sending the SQL injection payload This payload can be modified to executes SQL commands in the TSDB. Figure 5: SQL injection used to execute arbitrary SQL command The user can then delete all the historical data in the database: Figure 6: Example payload dropping the tables Steps to Reproduce
Recommendations• Sanitize all user-supplied input before executing it • Use prepared statements with parameterized queries when executing SQL statements Affected versions
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.10.5
6.10.6
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
+ 1 more Show less
6.9.2
Fixed in
7.0.0-rc3
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-42086
GHSA-ffq5-qpvf-xq7x
PYSEC-2026-105
Apr 22, 2026
OpenC3 COSMOS is Vulnerable to Self-XSS Through the Command Sender
4.6
/ 10
Medium
Network
Low
Low
Required
Unchanged
Low
Low
None
SummaryThe Command Sender UI uses an unsafe DetailsThe unsafe PoC
Below example uses ImpactLocal JavaScript execution in the user's browser Affected versions
5.0.10
5.0.11
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.10.0
5.10.1
5.11.0
5.11.1
+ 66 more Show less
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.2.0
5.20.0
5.3.0
5.4.0
5.4.1
5.4.2
5.4.3.pre.beta0
5.5.0
5.5.0.pre.beta0
5.5.1
5.5.2
5.5.2.pre.beta0
5.6.0
5.6.1
5.7.0
5.7.2
5.8.0
5.8.1
5.9.0
5.9.1
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.10.5
6.10.6
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
7.0.0.pre.rc1
7.0.0.pre.rc2
7.0.0.pre.rc3
Fixed in
7.0.0
References
Updated May 29, 2026 · Source: OSV.dev
CVE-2026-42085
GHSA-4jvx-93h3-f45h
PYSEC-2026-2243
Apr 22, 2026
OpenC3 COSMOS allows arbitrary writes to plugins directory via path-traversed config filenames
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
None
SummaryOpenC3 COSMOS contains a design flaw in the DetailsIn function PoC
ImpactModifying the data of other plugins Affected versions
5.0.10
5.0.11
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.10.0
5.10.1
5.11.0
5.11.1
+ 71 more Show less
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.2.0
5.20.0
5.3.0
5.4.0
5.4.1
5.4.2
5.4.3.pre.beta0
5.5.0
5.5.0.pre.beta0
5.5.1
5.5.2
5.5.2.pre.beta0
5.6.0
5.6.1
5.7.0
5.7.2
5.8.0
5.8.1
5.9.0
5.9.1
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
7.0.0
7.0.0.pre.rc1
7.0.0.pre.rc2
7.0.0.pre.rc3
7.0.1
7.1.0
7.1.1
7.2.0
7.2.1
7.3.0
Fixed in
6.10.5
7.0.0-rc3
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-42084
GHSA-wgx6-g857-jjf7
PYSEC-2026-2242
Apr 22, 2026
OpenC3 COSMOS: Hijacked session token can be used to reset password for persistence
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
SummaryThe OpenC3 password change functionality allows a user to change their password without providing the old password, by accepting a valid session token instead. In assumed breach scenarios, this behaviour can be exploited by an attacker who has already obtained a valid session token, to gain persistence in hijacked account (including admin) and prevent legitimate users from accessing the account. DetailsThe design flaw in authentication model (authentication.rb) allows for interchangeable use of password and session tokens for user authentication As old tokens are not revoked upon password reset, an attacker who has obtained a valid session token can continue to authenticate and change the account’s password even after the victim resets it, thereby maintaining persistent control over the compromised account. PoC
ImpactPersistence of an attacker who obtained valid session token and preventing legitimate users from account access Affected versions
5.0.10
5.0.11
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.10.0
5.10.1
5.11.0
5.11.1
+ 71 more Show less
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.2.0
5.20.0
5.3.0
5.4.0
5.4.1
5.4.2
5.4.3.pre.beta0
5.5.0
5.5.0.pre.beta0
5.5.1
5.5.2
5.5.2.pre.beta0
5.6.0
5.6.1
5.7.0
5.7.2
5.8.0
5.8.1
5.9.0
5.9.1
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
7.0.0
7.0.0.pre.rc1
7.0.0.pre.rc2
7.0.0.pre.rc3
7.0.1
7.1.0
7.1.1
7.2.0
7.2.1
7.3.0
Fixed in
6.10.5
7.0.0-rc3
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2025-68271
GHSA-w757-4qv9-mghp
Jan 13, 2026
openc3-api Vulnerable to Unauthenticated Remote Code Execution
10.0
/ 10
Critical
Network
Low
None
None
Changed
High
High
High
SummaryOpenC3 COSMOS contains a critical remote code execution vulnerability reachable through the JSON-RPC API. When a JSON-RPC request uses the string form of certain APIs, attacker-controlled parameter text is parsed into values using String#convert_to_value. For array-like inputs, convert_to_value executes eval(). Because the cmd code path parses the command string before calling authorize(), an unauthenticated attacker can trigger Ruby code execution even though the request ultimately fails authorization (401). Affected versions
5.0.10
5.0.11
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.10.0
5.10.1
5.11.0
5.11.1
+ 58 more Show less
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.2.0
5.20.0
5.3.0
5.4.0
5.4.1
5.4.2
5.4.3.pre.beta0
5.5.0
5.5.0.pre.beta0
5.5.1
5.5.2
5.5.2.pre.beta0
5.6.0
5.6.1
5.7.0
5.7.2
5.8.0
5.8.1
5.9.0
5.9.1
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
Fixed in
6.10.2
References
Updated Feb 03, 2026 · Source: OSV.dev |
6.9.0
minor
Dependencies (59)
+ 51 more
Changelog
Compare changes
|
|
6.8.1
patch
6 CVEs
CVE-2026-42088
GHSA-2wvh-87g2-89hr
PYSEC-2026-2245
Apr 23, 2026
OpenC3 COSMOS: Permissions Bypass Provides User Access to Unassigned Administrative Actions via Script Runner Tool
9.6
/ 10
Critical
Network
Low
Low
None
Changed
High
High
None
Vulnerability Type: Execution with Unnecessary Privileges Attack type: Authenticated remote Impact: Data disclosure/manipulation, privilege escalation Affected components: The following docker images: • Openc3inc/openc3-COSMOS-script-runner-api The Script Runner widget allows users to execute Python and Ruby scripts directly from the openc3-COSMOS-script-runner-api container. Because all the docker containers share a network, users can execute specially crafted scripts to bypass the API permissions check and perform administrative actions, including reading and modifying data inside the Redis database, which can be used to read secrets and change COSMOS settings, as well as read and write to the buckets service, which holds configuration, log, and plugin files. These actions are normally only available from the Admin Console or with administrative privileges. Any user with permission to create and run scripts can connect to any service in the docker network. Figure 1: Environment variables, including Redis credentials, found in the Script Runner container A Ruby script is used to expose the Redis username, password, hostname, and port. These credentials might also be found from the source code or through a brute-force attack. Figure 2: A Python script is used to add data to Redis and retrieve the new data
A Python script is then used to create a new entry in the Redis database called Figure 3: The new data found in the Redis database
The new entry was successfully added to the Redis database, as is confirmed by using Figure 4: Uploading file to change the plugin store URL setting Figure 5: The URL file was successfully changed Steps To Reproduce
Recommendations• Limit the permissions of the script runner API to prevent lower level users from performing administrative actions Affected versions
5.0.10
5.0.11
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.10.0
5.10.1
5.11.0
5.11.1
+ 63 more Show less
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.2.0
5.20.0
5.3.0
5.4.0
5.4.1
5.4.2
5.4.3.pre.beta0
5.5.0
5.5.0.pre.beta0
5.5.1
5.5.2
5.5.2.pre.beta0
5.6.0
5.6.1
5.7.0
5.7.2
5.8.0
5.8.1
5.9.0
5.9.1
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.10.5
6.10.6
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
Fixed in
7.0.0-rc3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-42087
GHSA-v529-vhwc-wfc5
PYSEC-2026-2244
Apr 23, 2026
OpenC3 COSMOS has SQL Injection in QuestDB Time-Series Database
9.6
/ 10
Critical
Network
Low
Low
None
Changed
High
High
None
Vulnerability Type: CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Attack type: Authenticated remote Impact: Telemetry data disclosure and deletion Affected components: openc3-tsdb (QuestDB) A SQL injection vulnerability exists in the Time-Series Database (TSDB) component of COSMOS. The Figure 1: Source code vulnerable to SQL injection
Additionally, the Figure 2: Source code showing the required permissions for the Figure 3: A normal request to the Figure 4: The request and response after sending the SQL injection payload This payload can be modified to executes SQL commands in the TSDB. Figure 5: SQL injection used to execute arbitrary SQL command The user can then delete all the historical data in the database: Figure 6: Example payload dropping the tables Steps to Reproduce
Recommendations• Sanitize all user-supplied input before executing it • Use prepared statements with parameterized queries when executing SQL statements Affected versions
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.10.5
6.10.6
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
+ 1 more Show less
6.9.2
Fixed in
7.0.0-rc3
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-42086
GHSA-ffq5-qpvf-xq7x
PYSEC-2026-105
Apr 22, 2026
OpenC3 COSMOS is Vulnerable to Self-XSS Through the Command Sender
4.6
/ 10
Medium
Network
Low
Low
Required
Unchanged
Low
Low
None
SummaryThe Command Sender UI uses an unsafe DetailsThe unsafe PoC
Below example uses ImpactLocal JavaScript execution in the user's browser Affected versions
5.0.10
5.0.11
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.10.0
5.10.1
5.11.0
5.11.1
+ 66 more Show less
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.2.0
5.20.0
5.3.0
5.4.0
5.4.1
5.4.2
5.4.3.pre.beta0
5.5.0
5.5.0.pre.beta0
5.5.1
5.5.2
5.5.2.pre.beta0
5.6.0
5.6.1
5.7.0
5.7.2
5.8.0
5.8.1
5.9.0
5.9.1
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.10.5
6.10.6
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
7.0.0.pre.rc1
7.0.0.pre.rc2
7.0.0.pre.rc3
Fixed in
7.0.0
References
Updated May 29, 2026 · Source: OSV.dev
CVE-2026-42085
GHSA-4jvx-93h3-f45h
PYSEC-2026-2243
Apr 22, 2026
OpenC3 COSMOS allows arbitrary writes to plugins directory via path-traversed config filenames
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
None
SummaryOpenC3 COSMOS contains a design flaw in the DetailsIn function PoC
ImpactModifying the data of other plugins Affected versions
5.0.10
5.0.11
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.10.0
5.10.1
5.11.0
5.11.1
+ 71 more Show less
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.2.0
5.20.0
5.3.0
5.4.0
5.4.1
5.4.2
5.4.3.pre.beta0
5.5.0
5.5.0.pre.beta0
5.5.1
5.5.2
5.5.2.pre.beta0
5.6.0
5.6.1
5.7.0
5.7.2
5.8.0
5.8.1
5.9.0
5.9.1
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
7.0.0
7.0.0.pre.rc1
7.0.0.pre.rc2
7.0.0.pre.rc3
7.0.1
7.1.0
7.1.1
7.2.0
7.2.1
7.3.0
Fixed in
6.10.5
7.0.0-rc3
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-42084
GHSA-wgx6-g857-jjf7
PYSEC-2026-2242
Apr 22, 2026
OpenC3 COSMOS: Hijacked session token can be used to reset password for persistence
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
SummaryThe OpenC3 password change functionality allows a user to change their password without providing the old password, by accepting a valid session token instead. In assumed breach scenarios, this behaviour can be exploited by an attacker who has already obtained a valid session token, to gain persistence in hijacked account (including admin) and prevent legitimate users from accessing the account. DetailsThe design flaw in authentication model (authentication.rb) allows for interchangeable use of password and session tokens for user authentication As old tokens are not revoked upon password reset, an attacker who has obtained a valid session token can continue to authenticate and change the account’s password even after the victim resets it, thereby maintaining persistent control over the compromised account. PoC
ImpactPersistence of an attacker who obtained valid session token and preventing legitimate users from account access Affected versions
5.0.10
5.0.11
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.10.0
5.10.1
5.11.0
5.11.1
+ 71 more Show less
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.2.0
5.20.0
5.3.0
5.4.0
5.4.1
5.4.2
5.4.3.pre.beta0
5.5.0
5.5.0.pre.beta0
5.5.1
5.5.2
5.5.2.pre.beta0
5.6.0
5.6.1
5.7.0
5.7.2
5.8.0
5.8.1
5.9.0
5.9.1
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
7.0.0
7.0.0.pre.rc1
7.0.0.pre.rc2
7.0.0.pre.rc3
7.0.1
7.1.0
7.1.1
7.2.0
7.2.1
7.3.0
Fixed in
6.10.5
7.0.0-rc3
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2025-68271
GHSA-w757-4qv9-mghp
Jan 13, 2026
openc3-api Vulnerable to Unauthenticated Remote Code Execution
10.0
/ 10
Critical
Network
Low
None
None
Changed
High
High
High
SummaryOpenC3 COSMOS contains a critical remote code execution vulnerability reachable through the JSON-RPC API. When a JSON-RPC request uses the string form of certain APIs, attacker-controlled parameter text is parsed into values using String#convert_to_value. For array-like inputs, convert_to_value executes eval(). Because the cmd code path parses the command string before calling authorize(), an unauthenticated attacker can trigger Ruby code execution even though the request ultimately fails authorization (401). Affected versions
5.0.10
5.0.11
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.10.0
5.10.1
5.11.0
5.11.1
+ 58 more Show less
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.2.0
5.20.0
5.3.0
5.4.0
5.4.1
5.4.2
5.4.3.pre.beta0
5.5.0
5.5.0.pre.beta0
5.5.1
5.5.2
5.5.2.pre.beta0
5.6.0
5.6.1
5.7.0
5.7.2
5.8.0
5.8.1
5.9.0
5.9.1
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
Fixed in
6.10.2
References
Updated Feb 03, 2026 · Source: OSV.dev |
6.8.1
patch
Dependencies (59)
+ 51 more
Changelog
Compare changes
|
|
6.8.0
minor
6 CVEs
CVE-2026-42088
GHSA-2wvh-87g2-89hr
PYSEC-2026-2245
Apr 23, 2026
OpenC3 COSMOS: Permissions Bypass Provides User Access to Unassigned Administrative Actions via Script Runner Tool
9.6
/ 10
Critical
Network
Low
Low
None
Changed
High
High
None
Vulnerability Type: Execution with Unnecessary Privileges Attack type: Authenticated remote Impact: Data disclosure/manipulation, privilege escalation Affected components: The following docker images: • Openc3inc/openc3-COSMOS-script-runner-api The Script Runner widget allows users to execute Python and Ruby scripts directly from the openc3-COSMOS-script-runner-api container. Because all the docker containers share a network, users can execute specially crafted scripts to bypass the API permissions check and perform administrative actions, including reading and modifying data inside the Redis database, which can be used to read secrets and change COSMOS settings, as well as read and write to the buckets service, which holds configuration, log, and plugin files. These actions are normally only available from the Admin Console or with administrative privileges. Any user with permission to create and run scripts can connect to any service in the docker network. Figure 1: Environment variables, including Redis credentials, found in the Script Runner container A Ruby script is used to expose the Redis username, password, hostname, and port. These credentials might also be found from the source code or through a brute-force attack. Figure 2: A Python script is used to add data to Redis and retrieve the new data
A Python script is then used to create a new entry in the Redis database called Figure 3: The new data found in the Redis database
The new entry was successfully added to the Redis database, as is confirmed by using Figure 4: Uploading file to change the plugin store URL setting Figure 5: The URL file was successfully changed Steps To Reproduce
Recommendations• Limit the permissions of the script runner API to prevent lower level users from performing administrative actions Affected versions
5.0.10
5.0.11
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.10.0
5.10.1
5.11.0
5.11.1
+ 63 more Show less
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.2.0
5.20.0
5.3.0
5.4.0
5.4.1
5.4.2
5.4.3.pre.beta0
5.5.0
5.5.0.pre.beta0
5.5.1
5.5.2
5.5.2.pre.beta0
5.6.0
5.6.1
5.7.0
5.7.2
5.8.0
5.8.1
5.9.0
5.9.1
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.10.5
6.10.6
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
Fixed in
7.0.0-rc3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-42087
GHSA-v529-vhwc-wfc5
PYSEC-2026-2244
Apr 23, 2026
OpenC3 COSMOS has SQL Injection in QuestDB Time-Series Database
9.6
/ 10
Critical
Network
Low
Low
None
Changed
High
High
None
Vulnerability Type: CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Attack type: Authenticated remote Impact: Telemetry data disclosure and deletion Affected components: openc3-tsdb (QuestDB) A SQL injection vulnerability exists in the Time-Series Database (TSDB) component of COSMOS. The Figure 1: Source code vulnerable to SQL injection
Additionally, the Figure 2: Source code showing the required permissions for the Figure 3: A normal request to the Figure 4: The request and response after sending the SQL injection payload This payload can be modified to executes SQL commands in the TSDB. Figure 5: SQL injection used to execute arbitrary SQL command The user can then delete all the historical data in the database: Figure 6: Example payload dropping the tables Steps to Reproduce
Recommendations• Sanitize all user-supplied input before executing it • Use prepared statements with parameterized queries when executing SQL statements Affected versions
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.10.5
6.10.6
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
+ 1 more Show less
6.9.2
Fixed in
7.0.0-rc3
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-42086
GHSA-ffq5-qpvf-xq7x
PYSEC-2026-105
Apr 22, 2026
OpenC3 COSMOS is Vulnerable to Self-XSS Through the Command Sender
4.6
/ 10
Medium
Network
Low
Low
Required
Unchanged
Low
Low
None
SummaryThe Command Sender UI uses an unsafe DetailsThe unsafe PoC
Below example uses ImpactLocal JavaScript execution in the user's browser Affected versions
5.0.10
5.0.11
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.10.0
5.10.1
5.11.0
5.11.1
+ 66 more Show less
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.2.0
5.20.0
5.3.0
5.4.0
5.4.1
5.4.2
5.4.3.pre.beta0
5.5.0
5.5.0.pre.beta0
5.5.1
5.5.2
5.5.2.pre.beta0
5.6.0
5.6.1
5.7.0
5.7.2
5.8.0
5.8.1
5.9.0
5.9.1
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.10.5
6.10.6
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
7.0.0.pre.rc1
7.0.0.pre.rc2
7.0.0.pre.rc3
Fixed in
7.0.0
References
Updated May 29, 2026 · Source: OSV.dev
CVE-2026-42085
GHSA-4jvx-93h3-f45h
PYSEC-2026-2243
Apr 22, 2026
OpenC3 COSMOS allows arbitrary writes to plugins directory via path-traversed config filenames
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
None
SummaryOpenC3 COSMOS contains a design flaw in the DetailsIn function PoC
ImpactModifying the data of other plugins Affected versions
5.0.10
5.0.11
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.10.0
5.10.1
5.11.0
5.11.1
+ 71 more Show less
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.2.0
5.20.0
5.3.0
5.4.0
5.4.1
5.4.2
5.4.3.pre.beta0
5.5.0
5.5.0.pre.beta0
5.5.1
5.5.2
5.5.2.pre.beta0
5.6.0
5.6.1
5.7.0
5.7.2
5.8.0
5.8.1
5.9.0
5.9.1
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
7.0.0
7.0.0.pre.rc1
7.0.0.pre.rc2
7.0.0.pre.rc3
7.0.1
7.1.0
7.1.1
7.2.0
7.2.1
7.3.0
Fixed in
6.10.5
7.0.0-rc3
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-42084
GHSA-wgx6-g857-jjf7
PYSEC-2026-2242
Apr 22, 2026
OpenC3 COSMOS: Hijacked session token can be used to reset password for persistence
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
SummaryThe OpenC3 password change functionality allows a user to change their password without providing the old password, by accepting a valid session token instead. In assumed breach scenarios, this behaviour can be exploited by an attacker who has already obtained a valid session token, to gain persistence in hijacked account (including admin) and prevent legitimate users from accessing the account. DetailsThe design flaw in authentication model (authentication.rb) allows for interchangeable use of password and session tokens for user authentication As old tokens are not revoked upon password reset, an attacker who has obtained a valid session token can continue to authenticate and change the account’s password even after the victim resets it, thereby maintaining persistent control over the compromised account. PoC
ImpactPersistence of an attacker who obtained valid session token and preventing legitimate users from account access Affected versions
5.0.10
5.0.11
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.10.0
5.10.1
5.11.0
5.11.1
+ 71 more Show less
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.2.0
5.20.0
5.3.0
5.4.0
5.4.1
5.4.2
5.4.3.pre.beta0
5.5.0
5.5.0.pre.beta0
5.5.1
5.5.2
5.5.2.pre.beta0
5.6.0
5.6.1
5.7.0
5.7.2
5.8.0
5.8.1
5.9.0
5.9.1
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
7.0.0
7.0.0.pre.rc1
7.0.0.pre.rc2
7.0.0.pre.rc3
7.0.1
7.1.0
7.1.1
7.2.0
7.2.1
7.3.0
Fixed in
6.10.5
7.0.0-rc3
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2025-68271
GHSA-w757-4qv9-mghp
Jan 13, 2026
openc3-api Vulnerable to Unauthenticated Remote Code Execution
10.0
/ 10
Critical
Network
Low
None
None
Changed
High
High
High
SummaryOpenC3 COSMOS contains a critical remote code execution vulnerability reachable through the JSON-RPC API. When a JSON-RPC request uses the string form of certain APIs, attacker-controlled parameter text is parsed into values using String#convert_to_value. For array-like inputs, convert_to_value executes eval(). Because the cmd code path parses the command string before calling authorize(), an unauthenticated attacker can trigger Ruby code execution even though the request ultimately fails authorization (401). Affected versions
5.0.10
5.0.11
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.10.0
5.10.1
5.11.0
5.11.1
+ 58 more Show less
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.2.0
5.20.0
5.3.0
5.4.0
5.4.1
5.4.2
5.4.3.pre.beta0
5.5.0
5.5.0.pre.beta0
5.5.1
5.5.2
5.5.2.pre.beta0
5.6.0
5.6.1
5.7.0
5.7.2
5.8.0
5.8.1
5.9.0
5.9.1
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
Fixed in
6.10.2
References
Updated Feb 03, 2026 · Source: OSV.dev |
6.8.0
minor
Dependencies (59)
+ 51 more
Changelog
Compare changes
|
|
6.7.0
minor
6 CVEs
CVE-2026-42088
GHSA-2wvh-87g2-89hr
PYSEC-2026-2245
Apr 23, 2026
OpenC3 COSMOS: Permissions Bypass Provides User Access to Unassigned Administrative Actions via Script Runner Tool
9.6
/ 10
Critical
Network
Low
Low
None
Changed
High
High
None
Vulnerability Type: Execution with Unnecessary Privileges Attack type: Authenticated remote Impact: Data disclosure/manipulation, privilege escalation Affected components: The following docker images: • Openc3inc/openc3-COSMOS-script-runner-api The Script Runner widget allows users to execute Python and Ruby scripts directly from the openc3-COSMOS-script-runner-api container. Because all the docker containers share a network, users can execute specially crafted scripts to bypass the API permissions check and perform administrative actions, including reading and modifying data inside the Redis database, which can be used to read secrets and change COSMOS settings, as well as read and write to the buckets service, which holds configuration, log, and plugin files. These actions are normally only available from the Admin Console or with administrative privileges. Any user with permission to create and run scripts can connect to any service in the docker network. Figure 1: Environment variables, including Redis credentials, found in the Script Runner container A Ruby script is used to expose the Redis username, password, hostname, and port. These credentials might also be found from the source code or through a brute-force attack. Figure 2: A Python script is used to add data to Redis and retrieve the new data
A Python script is then used to create a new entry in the Redis database called Figure 3: The new data found in the Redis database
The new entry was successfully added to the Redis database, as is confirmed by using Figure 4: Uploading file to change the plugin store URL setting Figure 5: The URL file was successfully changed Steps To Reproduce
Recommendations• Limit the permissions of the script runner API to prevent lower level users from performing administrative actions Affected versions
5.0.10
5.0.11
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.10.0
5.10.1
5.11.0
5.11.1
+ 63 more Show less
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.2.0
5.20.0
5.3.0
5.4.0
5.4.1
5.4.2
5.4.3.pre.beta0
5.5.0
5.5.0.pre.beta0
5.5.1
5.5.2
5.5.2.pre.beta0
5.6.0
5.6.1
5.7.0
5.7.2
5.8.0
5.8.1
5.9.0
5.9.1
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.10.5
6.10.6
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
Fixed in
7.0.0-rc3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-42087
GHSA-v529-vhwc-wfc5
PYSEC-2026-2244
Apr 23, 2026
OpenC3 COSMOS has SQL Injection in QuestDB Time-Series Database
9.6
/ 10
Critical
Network
Low
Low
None
Changed
High
High
None
Vulnerability Type: CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Attack type: Authenticated remote Impact: Telemetry data disclosure and deletion Affected components: openc3-tsdb (QuestDB) A SQL injection vulnerability exists in the Time-Series Database (TSDB) component of COSMOS. The Figure 1: Source code vulnerable to SQL injection
Additionally, the Figure 2: Source code showing the required permissions for the Figure 3: A normal request to the Figure 4: The request and response after sending the SQL injection payload This payload can be modified to executes SQL commands in the TSDB. Figure 5: SQL injection used to execute arbitrary SQL command The user can then delete all the historical data in the database: Figure 6: Example payload dropping the tables Steps to Reproduce
Recommendations• Sanitize all user-supplied input before executing it • Use prepared statements with parameterized queries when executing SQL statements Affected versions
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.10.5
6.10.6
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
+ 1 more Show less
6.9.2
Fixed in
7.0.0-rc3
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-42086
GHSA-ffq5-qpvf-xq7x
PYSEC-2026-105
Apr 22, 2026
OpenC3 COSMOS is Vulnerable to Self-XSS Through the Command Sender
4.6
/ 10
Medium
Network
Low
Low
Required
Unchanged
Low
Low
None
SummaryThe Command Sender UI uses an unsafe DetailsThe unsafe PoC
Below example uses ImpactLocal JavaScript execution in the user's browser Affected versions
5.0.10
5.0.11
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.10.0
5.10.1
5.11.0
5.11.1
+ 66 more Show less
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.2.0
5.20.0
5.3.0
5.4.0
5.4.1
5.4.2
5.4.3.pre.beta0
5.5.0
5.5.0.pre.beta0
5.5.1
5.5.2
5.5.2.pre.beta0
5.6.0
5.6.1
5.7.0
5.7.2
5.8.0
5.8.1
5.9.0
5.9.1
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.10.5
6.10.6
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
7.0.0.pre.rc1
7.0.0.pre.rc2
7.0.0.pre.rc3
Fixed in
7.0.0
References
Updated May 29, 2026 · Source: OSV.dev
CVE-2026-42085
GHSA-4jvx-93h3-f45h
PYSEC-2026-2243
Apr 22, 2026
OpenC3 COSMOS allows arbitrary writes to plugins directory via path-traversed config filenames
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
None
SummaryOpenC3 COSMOS contains a design flaw in the DetailsIn function PoC
ImpactModifying the data of other plugins Affected versions
5.0.10
5.0.11
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.10.0
5.10.1
5.11.0
5.11.1
+ 71 more Show less
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.2.0
5.20.0
5.3.0
5.4.0
5.4.1
5.4.2
5.4.3.pre.beta0
5.5.0
5.5.0.pre.beta0
5.5.1
5.5.2
5.5.2.pre.beta0
5.6.0
5.6.1
5.7.0
5.7.2
5.8.0
5.8.1
5.9.0
5.9.1
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
7.0.0
7.0.0.pre.rc1
7.0.0.pre.rc2
7.0.0.pre.rc3
7.0.1
7.1.0
7.1.1
7.2.0
7.2.1
7.3.0
Fixed in
6.10.5
7.0.0-rc3
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-42084
GHSA-wgx6-g857-jjf7
PYSEC-2026-2242
Apr 22, 2026
OpenC3 COSMOS: Hijacked session token can be used to reset password for persistence
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
SummaryThe OpenC3 password change functionality allows a user to change their password without providing the old password, by accepting a valid session token instead. In assumed breach scenarios, this behaviour can be exploited by an attacker who has already obtained a valid session token, to gain persistence in hijacked account (including admin) and prevent legitimate users from accessing the account. DetailsThe design flaw in authentication model (authentication.rb) allows for interchangeable use of password and session tokens for user authentication As old tokens are not revoked upon password reset, an attacker who has obtained a valid session token can continue to authenticate and change the account’s password even after the victim resets it, thereby maintaining persistent control over the compromised account. PoC
ImpactPersistence of an attacker who obtained valid session token and preventing legitimate users from account access Affected versions
5.0.10
5.0.11
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.10.0
5.10.1
5.11.0
5.11.1
+ 71 more Show less
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.2.0
5.20.0
5.3.0
5.4.0
5.4.1
5.4.2
5.4.3.pre.beta0
5.5.0
5.5.0.pre.beta0
5.5.1
5.5.2
5.5.2.pre.beta0
5.6.0
5.6.1
5.7.0
5.7.2
5.8.0
5.8.1
5.9.0
5.9.1
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
7.0.0
7.0.0.pre.rc1
7.0.0.pre.rc2
7.0.0.pre.rc3
7.0.1
7.1.0
7.1.1
7.2.0
7.2.1
7.3.0
Fixed in
6.10.5
7.0.0-rc3
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2025-68271
GHSA-w757-4qv9-mghp
Jan 13, 2026
openc3-api Vulnerable to Unauthenticated Remote Code Execution
10.0
/ 10
Critical
Network
Low
None
None
Changed
High
High
High
SummaryOpenC3 COSMOS contains a critical remote code execution vulnerability reachable through the JSON-RPC API. When a JSON-RPC request uses the string form of certain APIs, attacker-controlled parameter text is parsed into values using String#convert_to_value. For array-like inputs, convert_to_value executes eval(). Because the cmd code path parses the command string before calling authorize(), an unauthenticated attacker can trigger Ruby code execution even though the request ultimately fails authorization (401). Affected versions
5.0.10
5.0.11
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.10.0
5.10.1
5.11.0
5.11.1
+ 58 more Show less
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.2.0
5.20.0
5.3.0
5.4.0
5.4.1
5.4.2
5.4.3.pre.beta0
5.5.0
5.5.0.pre.beta0
5.5.1
5.5.2
5.5.2.pre.beta0
5.6.0
5.6.1
5.7.0
5.7.2
5.8.0
5.8.1
5.9.0
5.9.1
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
Fixed in
6.10.2
References
Updated Feb 03, 2026 · Source: OSV.dev |
6.7.0
minor
Dependencies (58)
+ 50 more
Changelog
Compare changes
|
|
6.6.0
minor
5 CVEs
CVE-2026-42088
GHSA-2wvh-87g2-89hr
PYSEC-2026-2245
Apr 23, 2026
OpenC3 COSMOS: Permissions Bypass Provides User Access to Unassigned Administrative Actions via Script Runner Tool
9.6
/ 10
Critical
Network
Low
Low
None
Changed
High
High
None
Vulnerability Type: Execution with Unnecessary Privileges Attack type: Authenticated remote Impact: Data disclosure/manipulation, privilege escalation Affected components: The following docker images: • Openc3inc/openc3-COSMOS-script-runner-api The Script Runner widget allows users to execute Python and Ruby scripts directly from the openc3-COSMOS-script-runner-api container. Because all the docker containers share a network, users can execute specially crafted scripts to bypass the API permissions check and perform administrative actions, including reading and modifying data inside the Redis database, which can be used to read secrets and change COSMOS settings, as well as read and write to the buckets service, which holds configuration, log, and plugin files. These actions are normally only available from the Admin Console or with administrative privileges. Any user with permission to create and run scripts can connect to any service in the docker network. Figure 1: Environment variables, including Redis credentials, found in the Script Runner container A Ruby script is used to expose the Redis username, password, hostname, and port. These credentials might also be found from the source code or through a brute-force attack. Figure 2: A Python script is used to add data to Redis and retrieve the new data
A Python script is then used to create a new entry in the Redis database called Figure 3: The new data found in the Redis database
The new entry was successfully added to the Redis database, as is confirmed by using Figure 4: Uploading file to change the plugin store URL setting Figure 5: The URL file was successfully changed Steps To Reproduce
Recommendations• Limit the permissions of the script runner API to prevent lower level users from performing administrative actions Affected versions
5.0.10
5.0.11
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.10.0
5.10.1
5.11.0
5.11.1
+ 63 more Show less
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.2.0
5.20.0
5.3.0
5.4.0
5.4.1
5.4.2
5.4.3.pre.beta0
5.5.0
5.5.0.pre.beta0
5.5.1
5.5.2
5.5.2.pre.beta0
5.6.0
5.6.1
5.7.0
5.7.2
5.8.0
5.8.1
5.9.0
5.9.1
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.10.5
6.10.6
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
Fixed in
7.0.0-rc3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-42086
GHSA-ffq5-qpvf-xq7x
PYSEC-2026-105
Apr 22, 2026
OpenC3 COSMOS is Vulnerable to Self-XSS Through the Command Sender
4.6
/ 10
Medium
Network
Low
Low
Required
Unchanged
Low
Low
None
SummaryThe Command Sender UI uses an unsafe DetailsThe unsafe PoC
Below example uses ImpactLocal JavaScript execution in the user's browser Affected versions
5.0.10
5.0.11
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.10.0
5.10.1
5.11.0
5.11.1
+ 66 more Show less
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.2.0
5.20.0
5.3.0
5.4.0
5.4.1
5.4.2
5.4.3.pre.beta0
5.5.0
5.5.0.pre.beta0
5.5.1
5.5.2
5.5.2.pre.beta0
5.6.0
5.6.1
5.7.0
5.7.2
5.8.0
5.8.1
5.9.0
5.9.1
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.10.5
6.10.6
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
7.0.0.pre.rc1
7.0.0.pre.rc2
7.0.0.pre.rc3
Fixed in
7.0.0
References
Updated May 29, 2026 · Source: OSV.dev
CVE-2026-42085
GHSA-4jvx-93h3-f45h
PYSEC-2026-2243
Apr 22, 2026
OpenC3 COSMOS allows arbitrary writes to plugins directory via path-traversed config filenames
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
None
SummaryOpenC3 COSMOS contains a design flaw in the DetailsIn function PoC
ImpactModifying the data of other plugins Affected versions
5.0.10
5.0.11
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.10.0
5.10.1
5.11.0
5.11.1
+ 71 more Show less
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.2.0
5.20.0
5.3.0
5.4.0
5.4.1
5.4.2
5.4.3.pre.beta0
5.5.0
5.5.0.pre.beta0
5.5.1
5.5.2
5.5.2.pre.beta0
5.6.0
5.6.1
5.7.0
5.7.2
5.8.0
5.8.1
5.9.0
5.9.1
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
7.0.0
7.0.0.pre.rc1
7.0.0.pre.rc2
7.0.0.pre.rc3
7.0.1
7.1.0
7.1.1
7.2.0
7.2.1
7.3.0
Fixed in
6.10.5
7.0.0-rc3
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-42084
GHSA-wgx6-g857-jjf7
PYSEC-2026-2242
Apr 22, 2026
OpenC3 COSMOS: Hijacked session token can be used to reset password for persistence
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
SummaryThe OpenC3 password change functionality allows a user to change their password without providing the old password, by accepting a valid session token instead. In assumed breach scenarios, this behaviour can be exploited by an attacker who has already obtained a valid session token, to gain persistence in hijacked account (including admin) and prevent legitimate users from accessing the account. DetailsThe design flaw in authentication model (authentication.rb) allows for interchangeable use of password and session tokens for user authentication As old tokens are not revoked upon password reset, an attacker who has obtained a valid session token can continue to authenticate and change the account’s password even after the victim resets it, thereby maintaining persistent control over the compromised account. PoC
ImpactPersistence of an attacker who obtained valid session token and preventing legitimate users from account access Affected versions
5.0.10
5.0.11
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.10.0
5.10.1
5.11.0
5.11.1
+ 71 more Show less
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.2.0
5.20.0
5.3.0
5.4.0
5.4.1
5.4.2
5.4.3.pre.beta0
5.5.0
5.5.0.pre.beta0
5.5.1
5.5.2
5.5.2.pre.beta0
5.6.0
5.6.1
5.7.0
5.7.2
5.8.0
5.8.1
5.9.0
5.9.1
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
7.0.0
7.0.0.pre.rc1
7.0.0.pre.rc2
7.0.0.pre.rc3
7.0.1
7.1.0
7.1.1
7.2.0
7.2.1
7.3.0
Fixed in
6.10.5
7.0.0-rc3
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2025-68271
GHSA-w757-4qv9-mghp
Jan 13, 2026
openc3-api Vulnerable to Unauthenticated Remote Code Execution
10.0
/ 10
Critical
Network
Low
None
None
Changed
High
High
High
SummaryOpenC3 COSMOS contains a critical remote code execution vulnerability reachable through the JSON-RPC API. When a JSON-RPC request uses the string form of certain APIs, attacker-controlled parameter text is parsed into values using String#convert_to_value. For array-like inputs, convert_to_value executes eval(). Because the cmd code path parses the command string before calling authorize(), an unauthenticated attacker can trigger Ruby code execution even though the request ultimately fails authorization (401). Affected versions
5.0.10
5.0.11
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.10.0
5.10.1
5.11.0
5.11.1
+ 58 more Show less
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.2.0
5.20.0
5.3.0
5.4.0
5.4.1
5.4.2
5.4.3.pre.beta0
5.5.0
5.5.0.pre.beta0
5.5.1
5.5.2
5.5.2.pre.beta0
5.6.0
5.6.1
5.7.0
5.7.2
5.8.0
5.8.1
5.9.0
5.9.1
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
Fixed in
6.10.2
References
Updated Feb 03, 2026 · Source: OSV.dev |
6.6.0
minor
Dependencies (54)
+ 46 more
Changelog
Compare changes
|
|
6.5.1
patch
5 CVEs
CVE-2026-42088
GHSA-2wvh-87g2-89hr
PYSEC-2026-2245
Apr 23, 2026
OpenC3 COSMOS: Permissions Bypass Provides User Access to Unassigned Administrative Actions via Script Runner Tool
9.6
/ 10
Critical
Network
Low
Low
None
Changed
High
High
None
Vulnerability Type: Execution with Unnecessary Privileges Attack type: Authenticated remote Impact: Data disclosure/manipulation, privilege escalation Affected components: The following docker images: • Openc3inc/openc3-COSMOS-script-runner-api The Script Runner widget allows users to execute Python and Ruby scripts directly from the openc3-COSMOS-script-runner-api container. Because all the docker containers share a network, users can execute specially crafted scripts to bypass the API permissions check and perform administrative actions, including reading and modifying data inside the Redis database, which can be used to read secrets and change COSMOS settings, as well as read and write to the buckets service, which holds configuration, log, and plugin files. These actions are normally only available from the Admin Console or with administrative privileges. Any user with permission to create and run scripts can connect to any service in the docker network. Figure 1: Environment variables, including Redis credentials, found in the Script Runner container A Ruby script is used to expose the Redis username, password, hostname, and port. These credentials might also be found from the source code or through a brute-force attack. Figure 2: A Python script is used to add data to Redis and retrieve the new data
A Python script is then used to create a new entry in the Redis database called Figure 3: The new data found in the Redis database
The new entry was successfully added to the Redis database, as is confirmed by using Figure 4: Uploading file to change the plugin store URL setting Figure 5: The URL file was successfully changed Steps To Reproduce
Recommendations• Limit the permissions of the script runner API to prevent lower level users from performing administrative actions Affected versions
5.0.10
5.0.11
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.10.0
5.10.1
5.11.0
5.11.1
+ 63 more Show less
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.2.0
5.20.0
5.3.0
5.4.0
5.4.1
5.4.2
5.4.3.pre.beta0
5.5.0
5.5.0.pre.beta0
5.5.1
5.5.2
5.5.2.pre.beta0
5.6.0
5.6.1
5.7.0
5.7.2
5.8.0
5.8.1
5.9.0
5.9.1
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.10.5
6.10.6
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
Fixed in
7.0.0-rc3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-42086
GHSA-ffq5-qpvf-xq7x
PYSEC-2026-105
Apr 22, 2026
OpenC3 COSMOS is Vulnerable to Self-XSS Through the Command Sender
4.6
/ 10
Medium
Network
Low
Low
Required
Unchanged
Low
Low
None
SummaryThe Command Sender UI uses an unsafe DetailsThe unsafe PoC
Below example uses ImpactLocal JavaScript execution in the user's browser Affected versions
5.0.10
5.0.11
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.10.0
5.10.1
5.11.0
5.11.1
+ 66 more Show less
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.2.0
5.20.0
5.3.0
5.4.0
5.4.1
5.4.2
5.4.3.pre.beta0
5.5.0
5.5.0.pre.beta0
5.5.1
5.5.2
5.5.2.pre.beta0
5.6.0
5.6.1
5.7.0
5.7.2
5.8.0
5.8.1
5.9.0
5.9.1
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.10.5
6.10.6
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
7.0.0.pre.rc1
7.0.0.pre.rc2
7.0.0.pre.rc3
Fixed in
7.0.0
References
Updated May 29, 2026 · Source: OSV.dev
CVE-2026-42085
GHSA-4jvx-93h3-f45h
PYSEC-2026-2243
Apr 22, 2026
OpenC3 COSMOS allows arbitrary writes to plugins directory via path-traversed config filenames
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
None
SummaryOpenC3 COSMOS contains a design flaw in the DetailsIn function PoC
ImpactModifying the data of other plugins Affected versions
5.0.10
5.0.11
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.10.0
5.10.1
5.11.0
5.11.1
+ 71 more Show less
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.2.0
5.20.0
5.3.0
5.4.0
5.4.1
5.4.2
5.4.3.pre.beta0
5.5.0
5.5.0.pre.beta0
5.5.1
5.5.2
5.5.2.pre.beta0
5.6.0
5.6.1
5.7.0
5.7.2
5.8.0
5.8.1
5.9.0
5.9.1
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
7.0.0
7.0.0.pre.rc1
7.0.0.pre.rc2
7.0.0.pre.rc3
7.0.1
7.1.0
7.1.1
7.2.0
7.2.1
7.3.0
Fixed in
6.10.5
7.0.0-rc3
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-42084
GHSA-wgx6-g857-jjf7
PYSEC-2026-2242
Apr 22, 2026
OpenC3 COSMOS: Hijacked session token can be used to reset password for persistence
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
SummaryThe OpenC3 password change functionality allows a user to change their password without providing the old password, by accepting a valid session token instead. In assumed breach scenarios, this behaviour can be exploited by an attacker who has already obtained a valid session token, to gain persistence in hijacked account (including admin) and prevent legitimate users from accessing the account. DetailsThe design flaw in authentication model (authentication.rb) allows for interchangeable use of password and session tokens for user authentication As old tokens are not revoked upon password reset, an attacker who has obtained a valid session token can continue to authenticate and change the account’s password even after the victim resets it, thereby maintaining persistent control over the compromised account. PoC
ImpactPersistence of an attacker who obtained valid session token and preventing legitimate users from account access Affected versions
5.0.10
5.0.11
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.10.0
5.10.1
5.11.0
5.11.1
+ 71 more Show less
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.2.0
5.20.0
5.3.0
5.4.0
5.4.1
5.4.2
5.4.3.pre.beta0
5.5.0
5.5.0.pre.beta0
5.5.1
5.5.2
5.5.2.pre.beta0
5.6.0
5.6.1
5.7.0
5.7.2
5.8.0
5.8.1
5.9.0
5.9.1
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
7.0.0
7.0.0.pre.rc1
7.0.0.pre.rc2
7.0.0.pre.rc3
7.0.1
7.1.0
7.1.1
7.2.0
7.2.1
7.3.0
Fixed in
6.10.5
7.0.0-rc3
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2025-68271
GHSA-w757-4qv9-mghp
Jan 13, 2026
openc3-api Vulnerable to Unauthenticated Remote Code Execution
10.0
/ 10
Critical
Network
Low
None
None
Changed
High
High
High
SummaryOpenC3 COSMOS contains a critical remote code execution vulnerability reachable through the JSON-RPC API. When a JSON-RPC request uses the string form of certain APIs, attacker-controlled parameter text is parsed into values using String#convert_to_value. For array-like inputs, convert_to_value executes eval(). Because the cmd code path parses the command string before calling authorize(), an unauthenticated attacker can trigger Ruby code execution even though the request ultimately fails authorization (401). Affected versions
5.0.10
5.0.11
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.10.0
5.10.1
5.11.0
5.11.1
+ 58 more Show less
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.2.0
5.20.0
5.3.0
5.4.0
5.4.1
5.4.2
5.4.3.pre.beta0
5.5.0
5.5.0.pre.beta0
5.5.1
5.5.2
5.5.2.pre.beta0
5.6.0
5.6.1
5.7.0
5.7.2
5.8.0
5.8.1
5.9.0
5.9.1
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
Fixed in
6.10.2
References
Updated Feb 03, 2026 · Source: OSV.dev |
6.5.1
patch
Dependencies (55)
+ 47 more
Changelog
Compare changes
|
|
6.5.0
minor
5 CVEs
CVE-2026-42088
GHSA-2wvh-87g2-89hr
PYSEC-2026-2245
Apr 23, 2026
OpenC3 COSMOS: Permissions Bypass Provides User Access to Unassigned Administrative Actions via Script Runner Tool
9.6
/ 10
Critical
Network
Low
Low
None
Changed
High
High
None
Vulnerability Type: Execution with Unnecessary Privileges Attack type: Authenticated remote Impact: Data disclosure/manipulation, privilege escalation Affected components: The following docker images: • Openc3inc/openc3-COSMOS-script-runner-api The Script Runner widget allows users to execute Python and Ruby scripts directly from the openc3-COSMOS-script-runner-api container. Because all the docker containers share a network, users can execute specially crafted scripts to bypass the API permissions check and perform administrative actions, including reading and modifying data inside the Redis database, which can be used to read secrets and change COSMOS settings, as well as read and write to the buckets service, which holds configuration, log, and plugin files. These actions are normally only available from the Admin Console or with administrative privileges. Any user with permission to create and run scripts can connect to any service in the docker network. Figure 1: Environment variables, including Redis credentials, found in the Script Runner container A Ruby script is used to expose the Redis username, password, hostname, and port. These credentials might also be found from the source code or through a brute-force attack. Figure 2: A Python script is used to add data to Redis and retrieve the new data
A Python script is then used to create a new entry in the Redis database called Figure 3: The new data found in the Redis database
The new entry was successfully added to the Redis database, as is confirmed by using Figure 4: Uploading file to change the plugin store URL setting Figure 5: The URL file was successfully changed Steps To Reproduce
Recommendations• Limit the permissions of the script runner API to prevent lower level users from performing administrative actions Affected versions
5.0.10
5.0.11
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.10.0
5.10.1
5.11.0
5.11.1
+ 63 more Show less
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.2.0
5.20.0
5.3.0
5.4.0
5.4.1
5.4.2
5.4.3.pre.beta0
5.5.0
5.5.0.pre.beta0
5.5.1
5.5.2
5.5.2.pre.beta0
5.6.0
5.6.1
5.7.0
5.7.2
5.8.0
5.8.1
5.9.0
5.9.1
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.10.5
6.10.6
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
Fixed in
7.0.0-rc3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-42086
GHSA-ffq5-qpvf-xq7x
PYSEC-2026-105
Apr 22, 2026
OpenC3 COSMOS is Vulnerable to Self-XSS Through the Command Sender
4.6
/ 10
Medium
Network
Low
Low
Required
Unchanged
Low
Low
None
SummaryThe Command Sender UI uses an unsafe DetailsThe unsafe PoC
Below example uses ImpactLocal JavaScript execution in the user's browser Affected versions
5.0.10
5.0.11
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.10.0
5.10.1
5.11.0
5.11.1
+ 66 more Show less
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.2.0
5.20.0
5.3.0
5.4.0
5.4.1
5.4.2
5.4.3.pre.beta0
5.5.0
5.5.0.pre.beta0
5.5.1
5.5.2
5.5.2.pre.beta0
5.6.0
5.6.1
5.7.0
5.7.2
5.8.0
5.8.1
5.9.0
5.9.1
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.10.5
6.10.6
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
7.0.0.pre.rc1
7.0.0.pre.rc2
7.0.0.pre.rc3
Fixed in
7.0.0
References
Updated May 29, 2026 · Source: OSV.dev
CVE-2026-42085
GHSA-4jvx-93h3-f45h
PYSEC-2026-2243
Apr 22, 2026
OpenC3 COSMOS allows arbitrary writes to plugins directory via path-traversed config filenames
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
None
SummaryOpenC3 COSMOS contains a design flaw in the DetailsIn function PoC
ImpactModifying the data of other plugins Affected versions
5.0.10
5.0.11
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.10.0
5.10.1
5.11.0
5.11.1
+ 71 more Show less
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.2.0
5.20.0
5.3.0
5.4.0
5.4.1
5.4.2
5.4.3.pre.beta0
5.5.0
5.5.0.pre.beta0
5.5.1
5.5.2
5.5.2.pre.beta0
5.6.0
5.6.1
5.7.0
5.7.2
5.8.0
5.8.1
5.9.0
5.9.1
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
7.0.0
7.0.0.pre.rc1
7.0.0.pre.rc2
7.0.0.pre.rc3
7.0.1
7.1.0
7.1.1
7.2.0
7.2.1
7.3.0
Fixed in
6.10.5
7.0.0-rc3
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-42084
GHSA-wgx6-g857-jjf7
PYSEC-2026-2242
Apr 22, 2026
OpenC3 COSMOS: Hijacked session token can be used to reset password for persistence
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
SummaryThe OpenC3 password change functionality allows a user to change their password without providing the old password, by accepting a valid session token instead. In assumed breach scenarios, this behaviour can be exploited by an attacker who has already obtained a valid session token, to gain persistence in hijacked account (including admin) and prevent legitimate users from accessing the account. DetailsThe design flaw in authentication model (authentication.rb) allows for interchangeable use of password and session tokens for user authentication As old tokens are not revoked upon password reset, an attacker who has obtained a valid session token can continue to authenticate and change the account’s password even after the victim resets it, thereby maintaining persistent control over the compromised account. PoC
ImpactPersistence of an attacker who obtained valid session token and preventing legitimate users from account access Affected versions
5.0.10
5.0.11
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.10.0
5.10.1
5.11.0
5.11.1
+ 71 more Show less
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.2.0
5.20.0
5.3.0
5.4.0
5.4.1
5.4.2
5.4.3.pre.beta0
5.5.0
5.5.0.pre.beta0
5.5.1
5.5.2
5.5.2.pre.beta0
5.6.0
5.6.1
5.7.0
5.7.2
5.8.0
5.8.1
5.9.0
5.9.1
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
7.0.0
7.0.0.pre.rc1
7.0.0.pre.rc2
7.0.0.pre.rc3
7.0.1
7.1.0
7.1.1
7.2.0
7.2.1
7.3.0
Fixed in
6.10.5
7.0.0-rc3
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2025-68271
GHSA-w757-4qv9-mghp
Jan 13, 2026
openc3-api Vulnerable to Unauthenticated Remote Code Execution
10.0
/ 10
Critical
Network
Low
None
None
Changed
High
High
High
SummaryOpenC3 COSMOS contains a critical remote code execution vulnerability reachable through the JSON-RPC API. When a JSON-RPC request uses the string form of certain APIs, attacker-controlled parameter text is parsed into values using String#convert_to_value. For array-like inputs, convert_to_value executes eval(). Because the cmd code path parses the command string before calling authorize(), an unauthenticated attacker can trigger Ruby code execution even though the request ultimately fails authorization (401). Affected versions
5.0.10
5.0.11
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.10.0
5.10.1
5.11.0
5.11.1
+ 58 more Show less
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.2.0
5.20.0
5.3.0
5.4.0
5.4.1
5.4.2
5.4.3.pre.beta0
5.5.0
5.5.0.pre.beta0
5.5.1
5.5.2
5.5.2.pre.beta0
5.6.0
5.6.1
5.7.0
5.7.2
5.8.0
5.8.1
5.9.0
5.9.1
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
Fixed in
6.10.2
References
Updated Feb 03, 2026 · Source: OSV.dev |
6.5.0
minor
Dependencies (54)
+ 46 more
Changelog
Compare changes
|
|
6.4.2
patch
5 CVEs
CVE-2026-42088
GHSA-2wvh-87g2-89hr
PYSEC-2026-2245
Apr 23, 2026
OpenC3 COSMOS: Permissions Bypass Provides User Access to Unassigned Administrative Actions via Script Runner Tool
9.6
/ 10
Critical
Network
Low
Low
None
Changed
High
High
None
Vulnerability Type: Execution with Unnecessary Privileges Attack type: Authenticated remote Impact: Data disclosure/manipulation, privilege escalation Affected components: The following docker images: • Openc3inc/openc3-COSMOS-script-runner-api The Script Runner widget allows users to execute Python and Ruby scripts directly from the openc3-COSMOS-script-runner-api container. Because all the docker containers share a network, users can execute specially crafted scripts to bypass the API permissions check and perform administrative actions, including reading and modifying data inside the Redis database, which can be used to read secrets and change COSMOS settings, as well as read and write to the buckets service, which holds configuration, log, and plugin files. These actions are normally only available from the Admin Console or with administrative privileges. Any user with permission to create and run scripts can connect to any service in the docker network. Figure 1: Environment variables, including Redis credentials, found in the Script Runner container A Ruby script is used to expose the Redis username, password, hostname, and port. These credentials might also be found from the source code or through a brute-force attack. Figure 2: A Python script is used to add data to Redis and retrieve the new data
A Python script is then used to create a new entry in the Redis database called Figure 3: The new data found in the Redis database
The new entry was successfully added to the Redis database, as is confirmed by using Figure 4: Uploading file to change the plugin store URL setting Figure 5: The URL file was successfully changed Steps To Reproduce
Recommendations• Limit the permissions of the script runner API to prevent lower level users from performing administrative actions Affected versions
5.0.10
5.0.11
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.10.0
5.10.1
5.11.0
5.11.1
+ 63 more Show less
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.2.0
5.20.0
5.3.0
5.4.0
5.4.1
5.4.2
5.4.3.pre.beta0
5.5.0
5.5.0.pre.beta0
5.5.1
5.5.2
5.5.2.pre.beta0
5.6.0
5.6.1
5.7.0
5.7.2
5.8.0
5.8.1
5.9.0
5.9.1
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.10.5
6.10.6
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
Fixed in
7.0.0-rc3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-42086
GHSA-ffq5-qpvf-xq7x
PYSEC-2026-105
Apr 22, 2026
OpenC3 COSMOS is Vulnerable to Self-XSS Through the Command Sender
4.6
/ 10
Medium
Network
Low
Low
Required
Unchanged
Low
Low
None
SummaryThe Command Sender UI uses an unsafe DetailsThe unsafe PoC
Below example uses ImpactLocal JavaScript execution in the user's browser Affected versions
5.0.10
5.0.11
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.10.0
5.10.1
5.11.0
5.11.1
+ 66 more Show less
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.2.0
5.20.0
5.3.0
5.4.0
5.4.1
5.4.2
5.4.3.pre.beta0
5.5.0
5.5.0.pre.beta0
5.5.1
5.5.2
5.5.2.pre.beta0
5.6.0
5.6.1
5.7.0
5.7.2
5.8.0
5.8.1
5.9.0
5.9.1
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.10.5
6.10.6
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
7.0.0.pre.rc1
7.0.0.pre.rc2
7.0.0.pre.rc3
Fixed in
7.0.0
References
Updated May 29, 2026 · Source: OSV.dev
CVE-2026-42085
GHSA-4jvx-93h3-f45h
PYSEC-2026-2243
Apr 22, 2026
OpenC3 COSMOS allows arbitrary writes to plugins directory via path-traversed config filenames
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
None
SummaryOpenC3 COSMOS contains a design flaw in the DetailsIn function PoC
ImpactModifying the data of other plugins Affected versions
5.0.10
5.0.11
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.10.0
5.10.1
5.11.0
5.11.1
+ 71 more Show less
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.2.0
5.20.0
5.3.0
5.4.0
5.4.1
5.4.2
5.4.3.pre.beta0
5.5.0
5.5.0.pre.beta0
5.5.1
5.5.2
5.5.2.pre.beta0
5.6.0
5.6.1
5.7.0
5.7.2
5.8.0
5.8.1
5.9.0
5.9.1
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
7.0.0
7.0.0.pre.rc1
7.0.0.pre.rc2
7.0.0.pre.rc3
7.0.1
7.1.0
7.1.1
7.2.0
7.2.1
7.3.0
Fixed in
6.10.5
7.0.0-rc3
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-42084
GHSA-wgx6-g857-jjf7
PYSEC-2026-2242
Apr 22, 2026
OpenC3 COSMOS: Hijacked session token can be used to reset password for persistence
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
SummaryThe OpenC3 password change functionality allows a user to change their password without providing the old password, by accepting a valid session token instead. In assumed breach scenarios, this behaviour can be exploited by an attacker who has already obtained a valid session token, to gain persistence in hijacked account (including admin) and prevent legitimate users from accessing the account. DetailsThe design flaw in authentication model (authentication.rb) allows for interchangeable use of password and session tokens for user authentication As old tokens are not revoked upon password reset, an attacker who has obtained a valid session token can continue to authenticate and change the account’s password even after the victim resets it, thereby maintaining persistent control over the compromised account. PoC
ImpactPersistence of an attacker who obtained valid session token and preventing legitimate users from account access Affected versions
5.0.10
5.0.11
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.10.0
5.10.1
5.11.0
5.11.1
+ 71 more Show less
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.2.0
5.20.0
5.3.0
5.4.0
5.4.1
5.4.2
5.4.3.pre.beta0
5.5.0
5.5.0.pre.beta0
5.5.1
5.5.2
5.5.2.pre.beta0
5.6.0
5.6.1
5.7.0
5.7.2
5.8.0
5.8.1
5.9.0
5.9.1
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
7.0.0
7.0.0.pre.rc1
7.0.0.pre.rc2
7.0.0.pre.rc3
7.0.1
7.1.0
7.1.1
7.2.0
7.2.1
7.3.0
Fixed in
6.10.5
7.0.0-rc3
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2025-68271
GHSA-w757-4qv9-mghp
Jan 13, 2026
openc3-api Vulnerable to Unauthenticated Remote Code Execution
10.0
/ 10
Critical
Network
Low
None
None
Changed
High
High
High
SummaryOpenC3 COSMOS contains a critical remote code execution vulnerability reachable through the JSON-RPC API. When a JSON-RPC request uses the string form of certain APIs, attacker-controlled parameter text is parsed into values using String#convert_to_value. For array-like inputs, convert_to_value executes eval(). Because the cmd code path parses the command string before calling authorize(), an unauthenticated attacker can trigger Ruby code execution even though the request ultimately fails authorization (401). Affected versions
5.0.10
5.0.11
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.10.0
5.10.1
5.11.0
5.11.1
+ 58 more Show less
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.2.0
5.20.0
5.3.0
5.4.0
5.4.1
5.4.2
5.4.3.pre.beta0
5.5.0
5.5.0.pre.beta0
5.5.1
5.5.2
5.5.2.pre.beta0
5.6.0
5.6.1
5.7.0
5.7.2
5.8.0
5.8.1
5.9.0
5.9.1
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
Fixed in
6.10.2
References
Updated Feb 03, 2026 · Source: OSV.dev |
6.4.2
patch
Dependencies (54)
+ 46 more
Changelog
Compare changes
|
|
6.4.1
patch
5 CVEs
CVE-2026-42088
GHSA-2wvh-87g2-89hr
PYSEC-2026-2245
Apr 23, 2026
OpenC3 COSMOS: Permissions Bypass Provides User Access to Unassigned Administrative Actions via Script Runner Tool
9.6
/ 10
Critical
Network
Low
Low
None
Changed
High
High
None
Vulnerability Type: Execution with Unnecessary Privileges Attack type: Authenticated remote Impact: Data disclosure/manipulation, privilege escalation Affected components: The following docker images: • Openc3inc/openc3-COSMOS-script-runner-api The Script Runner widget allows users to execute Python and Ruby scripts directly from the openc3-COSMOS-script-runner-api container. Because all the docker containers share a network, users can execute specially crafted scripts to bypass the API permissions check and perform administrative actions, including reading and modifying data inside the Redis database, which can be used to read secrets and change COSMOS settings, as well as read and write to the buckets service, which holds configuration, log, and plugin files. These actions are normally only available from the Admin Console or with administrative privileges. Any user with permission to create and run scripts can connect to any service in the docker network. Figure 1: Environment variables, including Redis credentials, found in the Script Runner container A Ruby script is used to expose the Redis username, password, hostname, and port. These credentials might also be found from the source code or through a brute-force attack. Figure 2: A Python script is used to add data to Redis and retrieve the new data
A Python script is then used to create a new entry in the Redis database called Figure 3: The new data found in the Redis database
The new entry was successfully added to the Redis database, as is confirmed by using Figure 4: Uploading file to change the plugin store URL setting Figure 5: The URL file was successfully changed Steps To Reproduce
Recommendations• Limit the permissions of the script runner API to prevent lower level users from performing administrative actions Affected versions
5.0.10
5.0.11
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.10.0
5.10.1
5.11.0
5.11.1
+ 63 more Show less
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.2.0
5.20.0
5.3.0
5.4.0
5.4.1
5.4.2
5.4.3.pre.beta0
5.5.0
5.5.0.pre.beta0
5.5.1
5.5.2
5.5.2.pre.beta0
5.6.0
5.6.1
5.7.0
5.7.2
5.8.0
5.8.1
5.9.0
5.9.1
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.10.5
6.10.6
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
Fixed in
7.0.0-rc3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-42086
GHSA-ffq5-qpvf-xq7x
PYSEC-2026-105
Apr 22, 2026
OpenC3 COSMOS is Vulnerable to Self-XSS Through the Command Sender
4.6
/ 10
Medium
Network
Low
Low
Required
Unchanged
Low
Low
None
SummaryThe Command Sender UI uses an unsafe DetailsThe unsafe PoC
Below example uses ImpactLocal JavaScript execution in the user's browser Affected versions
5.0.10
5.0.11
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.10.0
5.10.1
5.11.0
5.11.1
+ 66 more Show less
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.2.0
5.20.0
5.3.0
5.4.0
5.4.1
5.4.2
5.4.3.pre.beta0
5.5.0
5.5.0.pre.beta0
5.5.1
5.5.2
5.5.2.pre.beta0
5.6.0
5.6.1
5.7.0
5.7.2
5.8.0
5.8.1
5.9.0
5.9.1
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.10.5
6.10.6
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
7.0.0.pre.rc1
7.0.0.pre.rc2
7.0.0.pre.rc3
Fixed in
7.0.0
References
Updated May 29, 2026 · Source: OSV.dev
CVE-2026-42085
GHSA-4jvx-93h3-f45h
PYSEC-2026-2243
Apr 22, 2026
OpenC3 COSMOS allows arbitrary writes to plugins directory via path-traversed config filenames
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
None
SummaryOpenC3 COSMOS contains a design flaw in the DetailsIn function PoC
ImpactModifying the data of other plugins Affected versions
5.0.10
5.0.11
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.10.0
5.10.1
5.11.0
5.11.1
+ 71 more Show less
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.2.0
5.20.0
5.3.0
5.4.0
5.4.1
5.4.2
5.4.3.pre.beta0
5.5.0
5.5.0.pre.beta0
5.5.1
5.5.2
5.5.2.pre.beta0
5.6.0
5.6.1
5.7.0
5.7.2
5.8.0
5.8.1
5.9.0
5.9.1
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
7.0.0
7.0.0.pre.rc1
7.0.0.pre.rc2
7.0.0.pre.rc3
7.0.1
7.1.0
7.1.1
7.2.0
7.2.1
7.3.0
Fixed in
6.10.5
7.0.0-rc3
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-42084
GHSA-wgx6-g857-jjf7
PYSEC-2026-2242
Apr 22, 2026
OpenC3 COSMOS: Hijacked session token can be used to reset password for persistence
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
SummaryThe OpenC3 password change functionality allows a user to change their password without providing the old password, by accepting a valid session token instead. In assumed breach scenarios, this behaviour can be exploited by an attacker who has already obtained a valid session token, to gain persistence in hijacked account (including admin) and prevent legitimate users from accessing the account. DetailsThe design flaw in authentication model (authentication.rb) allows for interchangeable use of password and session tokens for user authentication As old tokens are not revoked upon password reset, an attacker who has obtained a valid session token can continue to authenticate and change the account’s password even after the victim resets it, thereby maintaining persistent control over the compromised account. PoC
ImpactPersistence of an attacker who obtained valid session token and preventing legitimate users from account access Affected versions
5.0.10
5.0.11
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.10.0
5.10.1
5.11.0
5.11.1
+ 71 more Show less
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.2.0
5.20.0
5.3.0
5.4.0
5.4.1
5.4.2
5.4.3.pre.beta0
5.5.0
5.5.0.pre.beta0
5.5.1
5.5.2
5.5.2.pre.beta0
5.6.0
5.6.1
5.7.0
5.7.2
5.8.0
5.8.1
5.9.0
5.9.1
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
7.0.0
7.0.0.pre.rc1
7.0.0.pre.rc2
7.0.0.pre.rc3
7.0.1
7.1.0
7.1.1
7.2.0
7.2.1
7.3.0
Fixed in
6.10.5
7.0.0-rc3
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2025-68271
GHSA-w757-4qv9-mghp
Jan 13, 2026
openc3-api Vulnerable to Unauthenticated Remote Code Execution
10.0
/ 10
Critical
Network
Low
None
None
Changed
High
High
High
SummaryOpenC3 COSMOS contains a critical remote code execution vulnerability reachable through the JSON-RPC API. When a JSON-RPC request uses the string form of certain APIs, attacker-controlled parameter text is parsed into values using String#convert_to_value. For array-like inputs, convert_to_value executes eval(). Because the cmd code path parses the command string before calling authorize(), an unauthenticated attacker can trigger Ruby code execution even though the request ultimately fails authorization (401). Affected versions
5.0.10
5.0.11
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.10.0
5.10.1
5.11.0
5.11.1
+ 58 more Show less
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.2.0
5.20.0
5.3.0
5.4.0
5.4.1
5.4.2
5.4.3.pre.beta0
5.5.0
5.5.0.pre.beta0
5.5.1
5.5.2
5.5.2.pre.beta0
5.6.0
5.6.1
5.7.0
5.7.2
5.8.0
5.8.1
5.9.0
5.9.1
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
Fixed in
6.10.2
References
Updated Feb 03, 2026 · Source: OSV.dev |
6.4.1
patch
Dependencies (54)
+ 46 more
Changelog
Compare changes
|
|
6.4.0
minor
5 CVEs
CVE-2026-42088
GHSA-2wvh-87g2-89hr
PYSEC-2026-2245
Apr 23, 2026
OpenC3 COSMOS: Permissions Bypass Provides User Access to Unassigned Administrative Actions via Script Runner Tool
9.6
/ 10
Critical
Network
Low
Low
None
Changed
High
High
None
Vulnerability Type: Execution with Unnecessary Privileges Attack type: Authenticated remote Impact: Data disclosure/manipulation, privilege escalation Affected components: The following docker images: • Openc3inc/openc3-COSMOS-script-runner-api The Script Runner widget allows users to execute Python and Ruby scripts directly from the openc3-COSMOS-script-runner-api container. Because all the docker containers share a network, users can execute specially crafted scripts to bypass the API permissions check and perform administrative actions, including reading and modifying data inside the Redis database, which can be used to read secrets and change COSMOS settings, as well as read and write to the buckets service, which holds configuration, log, and plugin files. These actions are normally only available from the Admin Console or with administrative privileges. Any user with permission to create and run scripts can connect to any service in the docker network. Figure 1: Environment variables, including Redis credentials, found in the Script Runner container A Ruby script is used to expose the Redis username, password, hostname, and port. These credentials might also be found from the source code or through a brute-force attack. Figure 2: A Python script is used to add data to Redis and retrieve the new data
A Python script is then used to create a new entry in the Redis database called Figure 3: The new data found in the Redis database
The new entry was successfully added to the Redis database, as is confirmed by using Figure 4: Uploading file to change the plugin store URL setting Figure 5: The URL file was successfully changed Steps To Reproduce
Recommendations• Limit the permissions of the script runner API to prevent lower level users from performing administrative actions Affected versions
5.0.10
5.0.11
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.10.0
5.10.1
5.11.0
5.11.1
+ 63 more Show less
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.2.0
5.20.0
5.3.0
5.4.0
5.4.1
5.4.2
5.4.3.pre.beta0
5.5.0
5.5.0.pre.beta0
5.5.1
5.5.2
5.5.2.pre.beta0
5.6.0
5.6.1
5.7.0
5.7.2
5.8.0
5.8.1
5.9.0
5.9.1
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.10.5
6.10.6
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
Fixed in
7.0.0-rc3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-42086
GHSA-ffq5-qpvf-xq7x
PYSEC-2026-105
Apr 22, 2026
OpenC3 COSMOS is Vulnerable to Self-XSS Through the Command Sender
4.6
/ 10
Medium
Network
Low
Low
Required
Unchanged
Low
Low
None
SummaryThe Command Sender UI uses an unsafe DetailsThe unsafe PoC
Below example uses ImpactLocal JavaScript execution in the user's browser Affected versions
5.0.10
5.0.11
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.10.0
5.10.1
5.11.0
5.11.1
+ 66 more Show less
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.2.0
5.20.0
5.3.0
5.4.0
5.4.1
5.4.2
5.4.3.pre.beta0
5.5.0
5.5.0.pre.beta0
5.5.1
5.5.2
5.5.2.pre.beta0
5.6.0
5.6.1
5.7.0
5.7.2
5.8.0
5.8.1
5.9.0
5.9.1
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.10.5
6.10.6
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
7.0.0.pre.rc1
7.0.0.pre.rc2
7.0.0.pre.rc3
Fixed in
7.0.0
References
Updated May 29, 2026 · Source: OSV.dev
CVE-2026-42085
GHSA-4jvx-93h3-f45h
PYSEC-2026-2243
Apr 22, 2026
OpenC3 COSMOS allows arbitrary writes to plugins directory via path-traversed config filenames
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
None
SummaryOpenC3 COSMOS contains a design flaw in the DetailsIn function PoC
ImpactModifying the data of other plugins Affected versions
5.0.10
5.0.11
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.10.0
5.10.1
5.11.0
5.11.1
+ 71 more Show less
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.2.0
5.20.0
5.3.0
5.4.0
5.4.1
5.4.2
5.4.3.pre.beta0
5.5.0
5.5.0.pre.beta0
5.5.1
5.5.2
5.5.2.pre.beta0
5.6.0
5.6.1
5.7.0
5.7.2
5.8.0
5.8.1
5.9.0
5.9.1
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
7.0.0
7.0.0.pre.rc1
7.0.0.pre.rc2
7.0.0.pre.rc3
7.0.1
7.1.0
7.1.1
7.2.0
7.2.1
7.3.0
Fixed in
6.10.5
7.0.0-rc3
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-42084
GHSA-wgx6-g857-jjf7
PYSEC-2026-2242
Apr 22, 2026
OpenC3 COSMOS: Hijacked session token can be used to reset password for persistence
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
SummaryThe OpenC3 password change functionality allows a user to change their password without providing the old password, by accepting a valid session token instead. In assumed breach scenarios, this behaviour can be exploited by an attacker who has already obtained a valid session token, to gain persistence in hijacked account (including admin) and prevent legitimate users from accessing the account. DetailsThe design flaw in authentication model (authentication.rb) allows for interchangeable use of password and session tokens for user authentication As old tokens are not revoked upon password reset, an attacker who has obtained a valid session token can continue to authenticate and change the account’s password even after the victim resets it, thereby maintaining persistent control over the compromised account. PoC
ImpactPersistence of an attacker who obtained valid session token and preventing legitimate users from account access Affected versions
5.0.10
5.0.11
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.10.0
5.10.1
5.11.0
5.11.1
+ 71 more Show less
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.2.0
5.20.0
5.3.0
5.4.0
5.4.1
5.4.2
5.4.3.pre.beta0
5.5.0
5.5.0.pre.beta0
5.5.1
5.5.2
5.5.2.pre.beta0
5.6.0
5.6.1
5.7.0
5.7.2
5.8.0
5.8.1
5.9.0
5.9.1
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
7.0.0
7.0.0.pre.rc1
7.0.0.pre.rc2
7.0.0.pre.rc3
7.0.1
7.1.0
7.1.1
7.2.0
7.2.1
7.3.0
Fixed in
6.10.5
7.0.0-rc3
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2025-68271
GHSA-w757-4qv9-mghp
Jan 13, 2026
openc3-api Vulnerable to Unauthenticated Remote Code Execution
10.0
/ 10
Critical
Network
Low
None
None
Changed
High
High
High
SummaryOpenC3 COSMOS contains a critical remote code execution vulnerability reachable through the JSON-RPC API. When a JSON-RPC request uses the string form of certain APIs, attacker-controlled parameter text is parsed into values using String#convert_to_value. For array-like inputs, convert_to_value executes eval(). Because the cmd code path parses the command string before calling authorize(), an unauthenticated attacker can trigger Ruby code execution even though the request ultimately fails authorization (401). Affected versions
5.0.10
5.0.11
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.10.0
5.10.1
5.11.0
5.11.1
+ 58 more Show less
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.2.0
5.20.0
5.3.0
5.4.0
5.4.1
5.4.2
5.4.3.pre.beta0
5.5.0
5.5.0.pre.beta0
5.5.1
5.5.2
5.5.2.pre.beta0
5.6.0
5.6.1
5.7.0
5.7.2
5.8.0
5.8.1
5.9.0
5.9.1
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
Fixed in
6.10.2
References
Updated Feb 03, 2026 · Source: OSV.dev |
6.4.0
minor
Dependencies (54)
+ 46 more
Changelog
Compare changes
|
|
6.3.0
minor
5 CVEs
CVE-2026-42088
GHSA-2wvh-87g2-89hr
PYSEC-2026-2245
Apr 23, 2026
OpenC3 COSMOS: Permissions Bypass Provides User Access to Unassigned Administrative Actions via Script Runner Tool
9.6
/ 10
Critical
Network
Low
Low
None
Changed
High
High
None
Vulnerability Type: Execution with Unnecessary Privileges Attack type: Authenticated remote Impact: Data disclosure/manipulation, privilege escalation Affected components: The following docker images: • Openc3inc/openc3-COSMOS-script-runner-api The Script Runner widget allows users to execute Python and Ruby scripts directly from the openc3-COSMOS-script-runner-api container. Because all the docker containers share a network, users can execute specially crafted scripts to bypass the API permissions check and perform administrative actions, including reading and modifying data inside the Redis database, which can be used to read secrets and change COSMOS settings, as well as read and write to the buckets service, which holds configuration, log, and plugin files. These actions are normally only available from the Admin Console or with administrative privileges. Any user with permission to create and run scripts can connect to any service in the docker network. Figure 1: Environment variables, including Redis credentials, found in the Script Runner container A Ruby script is used to expose the Redis username, password, hostname, and port. These credentials might also be found from the source code or through a brute-force attack. Figure 2: A Python script is used to add data to Redis and retrieve the new data
A Python script is then used to create a new entry in the Redis database called Figure 3: The new data found in the Redis database
The new entry was successfully added to the Redis database, as is confirmed by using Figure 4: Uploading file to change the plugin store URL setting Figure 5: The URL file was successfully changed Steps To Reproduce
Recommendations• Limit the permissions of the script runner API to prevent lower level users from performing administrative actions Affected versions
5.0.10
5.0.11
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.10.0
5.10.1
5.11.0
5.11.1
+ 63 more Show less
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.2.0
5.20.0
5.3.0
5.4.0
5.4.1
5.4.2
5.4.3.pre.beta0
5.5.0
5.5.0.pre.beta0
5.5.1
5.5.2
5.5.2.pre.beta0
5.6.0
5.6.1
5.7.0
5.7.2
5.8.0
5.8.1
5.9.0
5.9.1
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.10.5
6.10.6
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
Fixed in
7.0.0-rc3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-42086
GHSA-ffq5-qpvf-xq7x
PYSEC-2026-105
Apr 22, 2026
OpenC3 COSMOS is Vulnerable to Self-XSS Through the Command Sender
4.6
/ 10
Medium
Network
Low
Low
Required
Unchanged
Low
Low
None
SummaryThe Command Sender UI uses an unsafe DetailsThe unsafe PoC
Below example uses ImpactLocal JavaScript execution in the user's browser Affected versions
5.0.10
5.0.11
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.10.0
5.10.1
5.11.0
5.11.1
+ 66 more Show less
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.2.0
5.20.0
5.3.0
5.4.0
5.4.1
5.4.2
5.4.3.pre.beta0
5.5.0
5.5.0.pre.beta0
5.5.1
5.5.2
5.5.2.pre.beta0
5.6.0
5.6.1
5.7.0
5.7.2
5.8.0
5.8.1
5.9.0
5.9.1
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.10.5
6.10.6
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
7.0.0.pre.rc1
7.0.0.pre.rc2
7.0.0.pre.rc3
Fixed in
7.0.0
References
Updated May 29, 2026 · Source: OSV.dev
CVE-2026-42085
GHSA-4jvx-93h3-f45h
PYSEC-2026-2243
Apr 22, 2026
OpenC3 COSMOS allows arbitrary writes to plugins directory via path-traversed config filenames
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
None
SummaryOpenC3 COSMOS contains a design flaw in the DetailsIn function PoC
ImpactModifying the data of other plugins Affected versions
5.0.10
5.0.11
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.10.0
5.10.1
5.11.0
5.11.1
+ 71 more Show less
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.2.0
5.20.0
5.3.0
5.4.0
5.4.1
5.4.2
5.4.3.pre.beta0
5.5.0
5.5.0.pre.beta0
5.5.1
5.5.2
5.5.2.pre.beta0
5.6.0
5.6.1
5.7.0
5.7.2
5.8.0
5.8.1
5.9.0
5.9.1
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
7.0.0
7.0.0.pre.rc1
7.0.0.pre.rc2
7.0.0.pre.rc3
7.0.1
7.1.0
7.1.1
7.2.0
7.2.1
7.3.0
Fixed in
6.10.5
7.0.0-rc3
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-42084
GHSA-wgx6-g857-jjf7
PYSEC-2026-2242
Apr 22, 2026
OpenC3 COSMOS: Hijacked session token can be used to reset password for persistence
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
SummaryThe OpenC3 password change functionality allows a user to change their password without providing the old password, by accepting a valid session token instead. In assumed breach scenarios, this behaviour can be exploited by an attacker who has already obtained a valid session token, to gain persistence in hijacked account (including admin) and prevent legitimate users from accessing the account. DetailsThe design flaw in authentication model (authentication.rb) allows for interchangeable use of password and session tokens for user authentication As old tokens are not revoked upon password reset, an attacker who has obtained a valid session token can continue to authenticate and change the account’s password even after the victim resets it, thereby maintaining persistent control over the compromised account. PoC
ImpactPersistence of an attacker who obtained valid session token and preventing legitimate users from account access Affected versions
5.0.10
5.0.11
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.10.0
5.10.1
5.11.0
5.11.1
+ 71 more Show less
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.2.0
5.20.0
5.3.0
5.4.0
5.4.1
5.4.2
5.4.3.pre.beta0
5.5.0
5.5.0.pre.beta0
5.5.1
5.5.2
5.5.2.pre.beta0
5.6.0
5.6.1
5.7.0
5.7.2
5.8.0
5.8.1
5.9.0
5.9.1
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
7.0.0
7.0.0.pre.rc1
7.0.0.pre.rc2
7.0.0.pre.rc3
7.0.1
7.1.0
7.1.1
7.2.0
7.2.1
7.3.0
Fixed in
6.10.5
7.0.0-rc3
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2025-68271
GHSA-w757-4qv9-mghp
Jan 13, 2026
openc3-api Vulnerable to Unauthenticated Remote Code Execution
10.0
/ 10
Critical
Network
Low
None
None
Changed
High
High
High
SummaryOpenC3 COSMOS contains a critical remote code execution vulnerability reachable through the JSON-RPC API. When a JSON-RPC request uses the string form of certain APIs, attacker-controlled parameter text is parsed into values using String#convert_to_value. For array-like inputs, convert_to_value executes eval(). Because the cmd code path parses the command string before calling authorize(), an unauthenticated attacker can trigger Ruby code execution even though the request ultimately fails authorization (401). Affected versions
5.0.10
5.0.11
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.10.0
5.10.1
5.11.0
5.11.1
+ 58 more Show less
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.2.0
5.20.0
5.3.0
5.4.0
5.4.1
5.4.2
5.4.3.pre.beta0
5.5.0
5.5.0.pre.beta0
5.5.1
5.5.2
5.5.2.pre.beta0
5.6.0
5.6.1
5.7.0
5.7.2
5.8.0
5.8.1
5.9.0
5.9.1
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
Fixed in
6.10.2
References
Updated Feb 03, 2026 · Source: OSV.dev |
6.3.0
minor
Dependencies (54)
+ 46 more
Changelog
Compare changes
|
|
6.2.1
patch
5 CVEs
CVE-2026-42088
GHSA-2wvh-87g2-89hr
PYSEC-2026-2245
Apr 23, 2026
OpenC3 COSMOS: Permissions Bypass Provides User Access to Unassigned Administrative Actions via Script Runner Tool
9.6
/ 10
Critical
Network
Low
Low
None
Changed
High
High
None
Vulnerability Type: Execution with Unnecessary Privileges Attack type: Authenticated remote Impact: Data disclosure/manipulation, privilege escalation Affected components: The following docker images: • Openc3inc/openc3-COSMOS-script-runner-api The Script Runner widget allows users to execute Python and Ruby scripts directly from the openc3-COSMOS-script-runner-api container. Because all the docker containers share a network, users can execute specially crafted scripts to bypass the API permissions check and perform administrative actions, including reading and modifying data inside the Redis database, which can be used to read secrets and change COSMOS settings, as well as read and write to the buckets service, which holds configuration, log, and plugin files. These actions are normally only available from the Admin Console or with administrative privileges. Any user with permission to create and run scripts can connect to any service in the docker network. Figure 1: Environment variables, including Redis credentials, found in the Script Runner container A Ruby script is used to expose the Redis username, password, hostname, and port. These credentials might also be found from the source code or through a brute-force attack. Figure 2: A Python script is used to add data to Redis and retrieve the new data
A Python script is then used to create a new entry in the Redis database called Figure 3: The new data found in the Redis database
The new entry was successfully added to the Redis database, as is confirmed by using Figure 4: Uploading file to change the plugin store URL setting Figure 5: The URL file was successfully changed Steps To Reproduce
Recommendations• Limit the permissions of the script runner API to prevent lower level users from performing administrative actions Affected versions
5.0.10
5.0.11
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.10.0
5.10.1
5.11.0
5.11.1
+ 63 more Show less
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.2.0
5.20.0
5.3.0
5.4.0
5.4.1
5.4.2
5.4.3.pre.beta0
5.5.0
5.5.0.pre.beta0
5.5.1
5.5.2
5.5.2.pre.beta0
5.6.0
5.6.1
5.7.0
5.7.2
5.8.0
5.8.1
5.9.0
5.9.1
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.10.5
6.10.6
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
Fixed in
7.0.0-rc3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-42086
GHSA-ffq5-qpvf-xq7x
PYSEC-2026-105
Apr 22, 2026
OpenC3 COSMOS is Vulnerable to Self-XSS Through the Command Sender
4.6
/ 10
Medium
Network
Low
Low
Required
Unchanged
Low
Low
None
SummaryThe Command Sender UI uses an unsafe DetailsThe unsafe PoC
Below example uses ImpactLocal JavaScript execution in the user's browser Affected versions
5.0.10
5.0.11
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.10.0
5.10.1
5.11.0
5.11.1
+ 66 more Show less
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.2.0
5.20.0
5.3.0
5.4.0
5.4.1
5.4.2
5.4.3.pre.beta0
5.5.0
5.5.0.pre.beta0
5.5.1
5.5.2
5.5.2.pre.beta0
5.6.0
5.6.1
5.7.0
5.7.2
5.8.0
5.8.1
5.9.0
5.9.1
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.10.5
6.10.6
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
7.0.0.pre.rc1
7.0.0.pre.rc2
7.0.0.pre.rc3
Fixed in
7.0.0
References
Updated May 29, 2026 · Source: OSV.dev
CVE-2026-42085
GHSA-4jvx-93h3-f45h
PYSEC-2026-2243
Apr 22, 2026
OpenC3 COSMOS allows arbitrary writes to plugins directory via path-traversed config filenames
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
None
SummaryOpenC3 COSMOS contains a design flaw in the DetailsIn function PoC
ImpactModifying the data of other plugins Affected versions
5.0.10
5.0.11
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.10.0
5.10.1
5.11.0
5.11.1
+ 71 more Show less
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.2.0
5.20.0
5.3.0
5.4.0
5.4.1
5.4.2
5.4.3.pre.beta0
5.5.0
5.5.0.pre.beta0
5.5.1
5.5.2
5.5.2.pre.beta0
5.6.0
5.6.1
5.7.0
5.7.2
5.8.0
5.8.1
5.9.0
5.9.1
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
7.0.0
7.0.0.pre.rc1
7.0.0.pre.rc2
7.0.0.pre.rc3
7.0.1
7.1.0
7.1.1
7.2.0
7.2.1
7.3.0
Fixed in
6.10.5
7.0.0-rc3
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-42084
GHSA-wgx6-g857-jjf7
PYSEC-2026-2242
Apr 22, 2026
OpenC3 COSMOS: Hijacked session token can be used to reset password for persistence
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
SummaryThe OpenC3 password change functionality allows a user to change their password without providing the old password, by accepting a valid session token instead. In assumed breach scenarios, this behaviour can be exploited by an attacker who has already obtained a valid session token, to gain persistence in hijacked account (including admin) and prevent legitimate users from accessing the account. DetailsThe design flaw in authentication model (authentication.rb) allows for interchangeable use of password and session tokens for user authentication As old tokens are not revoked upon password reset, an attacker who has obtained a valid session token can continue to authenticate and change the account’s password even after the victim resets it, thereby maintaining persistent control over the compromised account. PoC
ImpactPersistence of an attacker who obtained valid session token and preventing legitimate users from account access Affected versions
5.0.10
5.0.11
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.10.0
5.10.1
5.11.0
5.11.1
+ 71 more Show less
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.2.0
5.20.0
5.3.0
5.4.0
5.4.1
5.4.2
5.4.3.pre.beta0
5.5.0
5.5.0.pre.beta0
5.5.1
5.5.2
5.5.2.pre.beta0
5.6.0
5.6.1
5.7.0
5.7.2
5.8.0
5.8.1
5.9.0
5.9.1
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
7.0.0
7.0.0.pre.rc1
7.0.0.pre.rc2
7.0.0.pre.rc3
7.0.1
7.1.0
7.1.1
7.2.0
7.2.1
7.3.0
Fixed in
6.10.5
7.0.0-rc3
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2025-68271
GHSA-w757-4qv9-mghp
Jan 13, 2026
openc3-api Vulnerable to Unauthenticated Remote Code Execution
10.0
/ 10
Critical
Network
Low
None
None
Changed
High
High
High
SummaryOpenC3 COSMOS contains a critical remote code execution vulnerability reachable through the JSON-RPC API. When a JSON-RPC request uses the string form of certain APIs, attacker-controlled parameter text is parsed into values using String#convert_to_value. For array-like inputs, convert_to_value executes eval(). Because the cmd code path parses the command string before calling authorize(), an unauthenticated attacker can trigger Ruby code execution even though the request ultimately fails authorization (401). Affected versions
5.0.10
5.0.11
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.10.0
5.10.1
5.11.0
5.11.1
+ 58 more Show less
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.2.0
5.20.0
5.3.0
5.4.0
5.4.1
5.4.2
5.4.3.pre.beta0
5.5.0
5.5.0.pre.beta0
5.5.1
5.5.2
5.5.2.pre.beta0
5.6.0
5.6.1
5.7.0
5.7.2
5.8.0
5.8.1
5.9.0
5.9.1
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
Fixed in
6.10.2
References
Updated Feb 03, 2026 · Source: OSV.dev |
6.2.1
patch
Dependencies (54)
+ 46 more
Changelog
Compare changes
|
|
6.2.0
minor
5 CVEs
CVE-2026-42088
GHSA-2wvh-87g2-89hr
PYSEC-2026-2245
Apr 23, 2026
OpenC3 COSMOS: Permissions Bypass Provides User Access to Unassigned Administrative Actions via Script Runner Tool
9.6
/ 10
Critical
Network
Low
Low
None
Changed
High
High
None
Vulnerability Type: Execution with Unnecessary Privileges Attack type: Authenticated remote Impact: Data disclosure/manipulation, privilege escalation Affected components: The following docker images: • Openc3inc/openc3-COSMOS-script-runner-api The Script Runner widget allows users to execute Python and Ruby scripts directly from the openc3-COSMOS-script-runner-api container. Because all the docker containers share a network, users can execute specially crafted scripts to bypass the API permissions check and perform administrative actions, including reading and modifying data inside the Redis database, which can be used to read secrets and change COSMOS settings, as well as read and write to the buckets service, which holds configuration, log, and plugin files. These actions are normally only available from the Admin Console or with administrative privileges. Any user with permission to create and run scripts can connect to any service in the docker network. Figure 1: Environment variables, including Redis credentials, found in the Script Runner container A Ruby script is used to expose the Redis username, password, hostname, and port. These credentials might also be found from the source code or through a brute-force attack. Figure 2: A Python script is used to add data to Redis and retrieve the new data
A Python script is then used to create a new entry in the Redis database called Figure 3: The new data found in the Redis database
The new entry was successfully added to the Redis database, as is confirmed by using Figure 4: Uploading file to change the plugin store URL setting Figure 5: The URL file was successfully changed Steps To Reproduce
Recommendations• Limit the permissions of the script runner API to prevent lower level users from performing administrative actions Affected versions
5.0.10
5.0.11
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.10.0
5.10.1
5.11.0
5.11.1
+ 63 more Show less
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.2.0
5.20.0
5.3.0
5.4.0
5.4.1
5.4.2
5.4.3.pre.beta0
5.5.0
5.5.0.pre.beta0
5.5.1
5.5.2
5.5.2.pre.beta0
5.6.0
5.6.1
5.7.0
5.7.2
5.8.0
5.8.1
5.9.0
5.9.1
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.10.5
6.10.6
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
Fixed in
7.0.0-rc3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-42086
GHSA-ffq5-qpvf-xq7x
PYSEC-2026-105
Apr 22, 2026
OpenC3 COSMOS is Vulnerable to Self-XSS Through the Command Sender
4.6
/ 10
Medium
Network
Low
Low
Required
Unchanged
Low
Low
None
SummaryThe Command Sender UI uses an unsafe DetailsThe unsafe PoC
Below example uses ImpactLocal JavaScript execution in the user's browser Affected versions
5.0.10
5.0.11
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.10.0
5.10.1
5.11.0
5.11.1
+ 66 more Show less
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.2.0
5.20.0
5.3.0
5.4.0
5.4.1
5.4.2
5.4.3.pre.beta0
5.5.0
5.5.0.pre.beta0
5.5.1
5.5.2
5.5.2.pre.beta0
5.6.0
5.6.1
5.7.0
5.7.2
5.8.0
5.8.1
5.9.0
5.9.1
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.10.5
6.10.6
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
7.0.0.pre.rc1
7.0.0.pre.rc2
7.0.0.pre.rc3
Fixed in
7.0.0
References
Updated May 29, 2026 · Source: OSV.dev
CVE-2026-42085
GHSA-4jvx-93h3-f45h
PYSEC-2026-2243
Apr 22, 2026
OpenC3 COSMOS allows arbitrary writes to plugins directory via path-traversed config filenames
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
None
SummaryOpenC3 COSMOS contains a design flaw in the DetailsIn function PoC
ImpactModifying the data of other plugins Affected versions
5.0.10
5.0.11
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.10.0
5.10.1
5.11.0
5.11.1
+ 71 more Show less
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.2.0
5.20.0
5.3.0
5.4.0
5.4.1
5.4.2
5.4.3.pre.beta0
5.5.0
5.5.0.pre.beta0
5.5.1
5.5.2
5.5.2.pre.beta0
5.6.0
5.6.1
5.7.0
5.7.2
5.8.0
5.8.1
5.9.0
5.9.1
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
7.0.0
7.0.0.pre.rc1
7.0.0.pre.rc2
7.0.0.pre.rc3
7.0.1
7.1.0
7.1.1
7.2.0
7.2.1
7.3.0
Fixed in
6.10.5
7.0.0-rc3
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-42084
GHSA-wgx6-g857-jjf7
PYSEC-2026-2242
Apr 22, 2026
OpenC3 COSMOS: Hijacked session token can be used to reset password for persistence
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
SummaryThe OpenC3 password change functionality allows a user to change their password without providing the old password, by accepting a valid session token instead. In assumed breach scenarios, this behaviour can be exploited by an attacker who has already obtained a valid session token, to gain persistence in hijacked account (including admin) and prevent legitimate users from accessing the account. DetailsThe design flaw in authentication model (authentication.rb) allows for interchangeable use of password and session tokens for user authentication As old tokens are not revoked upon password reset, an attacker who has obtained a valid session token can continue to authenticate and change the account’s password even after the victim resets it, thereby maintaining persistent control over the compromised account. PoC
ImpactPersistence of an attacker who obtained valid session token and preventing legitimate users from account access Affected versions
5.0.10
5.0.11
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.10.0
5.10.1
5.11.0
5.11.1
+ 71 more Show less
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.2.0
5.20.0
5.3.0
5.4.0
5.4.1
5.4.2
5.4.3.pre.beta0
5.5.0
5.5.0.pre.beta0
5.5.1
5.5.2
5.5.2.pre.beta0
5.6.0
5.6.1
5.7.0
5.7.2
5.8.0
5.8.1
5.9.0
5.9.1
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
7.0.0
7.0.0.pre.rc1
7.0.0.pre.rc2
7.0.0.pre.rc3
7.0.1
7.1.0
7.1.1
7.2.0
7.2.1
7.3.0
Fixed in
6.10.5
7.0.0-rc3
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2025-68271
GHSA-w757-4qv9-mghp
Jan 13, 2026
openc3-api Vulnerable to Unauthenticated Remote Code Execution
10.0
/ 10
Critical
Network
Low
None
None
Changed
High
High
High
SummaryOpenC3 COSMOS contains a critical remote code execution vulnerability reachable through the JSON-RPC API. When a JSON-RPC request uses the string form of certain APIs, attacker-controlled parameter text is parsed into values using String#convert_to_value. For array-like inputs, convert_to_value executes eval(). Because the cmd code path parses the command string before calling authorize(), an unauthenticated attacker can trigger Ruby code execution even though the request ultimately fails authorization (401). Affected versions
5.0.10
5.0.11
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.10.0
5.10.1
5.11.0
5.11.1
+ 58 more Show less
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.2.0
5.20.0
5.3.0
5.4.0
5.4.1
5.4.2
5.4.3.pre.beta0
5.5.0
5.5.0.pre.beta0
5.5.1
5.5.2
5.5.2.pre.beta0
5.6.0
5.6.1
5.7.0
5.7.2
5.8.0
5.8.1
5.9.0
5.9.1
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
Fixed in
6.10.2
References
Updated Feb 03, 2026 · Source: OSV.dev |
6.2.0
minor
Dependencies (54)
+ 46 more
Changelog
Compare changes
|
|
6.1.0
minor
5 CVEs
CVE-2026-42088
GHSA-2wvh-87g2-89hr
PYSEC-2026-2245
Apr 23, 2026
OpenC3 COSMOS: Permissions Bypass Provides User Access to Unassigned Administrative Actions via Script Runner Tool
9.6
/ 10
Critical
Network
Low
Low
None
Changed
High
High
None
Vulnerability Type: Execution with Unnecessary Privileges Attack type: Authenticated remote Impact: Data disclosure/manipulation, privilege escalation Affected components: The following docker images: • Openc3inc/openc3-COSMOS-script-runner-api The Script Runner widget allows users to execute Python and Ruby scripts directly from the openc3-COSMOS-script-runner-api container. Because all the docker containers share a network, users can execute specially crafted scripts to bypass the API permissions check and perform administrative actions, including reading and modifying data inside the Redis database, which can be used to read secrets and change COSMOS settings, as well as read and write to the buckets service, which holds configuration, log, and plugin files. These actions are normally only available from the Admin Console or with administrative privileges. Any user with permission to create and run scripts can connect to any service in the docker network. Figure 1: Environment variables, including Redis credentials, found in the Script Runner container A Ruby script is used to expose the Redis username, password, hostname, and port. These credentials might also be found from the source code or through a brute-force attack. Figure 2: A Python script is used to add data to Redis and retrieve the new data
A Python script is then used to create a new entry in the Redis database called Figure 3: The new data found in the Redis database
The new entry was successfully added to the Redis database, as is confirmed by using Figure 4: Uploading file to change the plugin store URL setting Figure 5: The URL file was successfully changed Steps To Reproduce
Recommendations• Limit the permissions of the script runner API to prevent lower level users from performing administrative actions Affected versions
5.0.10
5.0.11
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.10.0
5.10.1
5.11.0
5.11.1
+ 63 more Show less
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.2.0
5.20.0
5.3.0
5.4.0
5.4.1
5.4.2
5.4.3.pre.beta0
5.5.0
5.5.0.pre.beta0
5.5.1
5.5.2
5.5.2.pre.beta0
5.6.0
5.6.1
5.7.0
5.7.2
5.8.0
5.8.1
5.9.0
5.9.1
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.10.5
6.10.6
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
Fixed in
7.0.0-rc3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-42086
GHSA-ffq5-qpvf-xq7x
PYSEC-2026-105
Apr 22, 2026
OpenC3 COSMOS is Vulnerable to Self-XSS Through the Command Sender
4.6
/ 10
Medium
Network
Low
Low
Required
Unchanged
Low
Low
None
SummaryThe Command Sender UI uses an unsafe DetailsThe unsafe PoC
Below example uses ImpactLocal JavaScript execution in the user's browser Affected versions
5.0.10
5.0.11
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.10.0
5.10.1
5.11.0
5.11.1
+ 66 more Show less
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.2.0
5.20.0
5.3.0
5.4.0
5.4.1
5.4.2
5.4.3.pre.beta0
5.5.0
5.5.0.pre.beta0
5.5.1
5.5.2
5.5.2.pre.beta0
5.6.0
5.6.1
5.7.0
5.7.2
5.8.0
5.8.1
5.9.0
5.9.1
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.10.5
6.10.6
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
7.0.0.pre.rc1
7.0.0.pre.rc2
7.0.0.pre.rc3
Fixed in
7.0.0
References
Updated May 29, 2026 · Source: OSV.dev
CVE-2026-42085
GHSA-4jvx-93h3-f45h
PYSEC-2026-2243
Apr 22, 2026
OpenC3 COSMOS allows arbitrary writes to plugins directory via path-traversed config filenames
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
None
SummaryOpenC3 COSMOS contains a design flaw in the DetailsIn function PoC
ImpactModifying the data of other plugins Affected versions
5.0.10
5.0.11
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.10.0
5.10.1
5.11.0
5.11.1
+ 71 more Show less
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.2.0
5.20.0
5.3.0
5.4.0
5.4.1
5.4.2
5.4.3.pre.beta0
5.5.0
5.5.0.pre.beta0
5.5.1
5.5.2
5.5.2.pre.beta0
5.6.0
5.6.1
5.7.0
5.7.2
5.8.0
5.8.1
5.9.0
5.9.1
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
7.0.0
7.0.0.pre.rc1
7.0.0.pre.rc2
7.0.0.pre.rc3
7.0.1
7.1.0
7.1.1
7.2.0
7.2.1
7.3.0
Fixed in
6.10.5
7.0.0-rc3
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-42084
GHSA-wgx6-g857-jjf7
PYSEC-2026-2242
Apr 22, 2026
OpenC3 COSMOS: Hijacked session token can be used to reset password for persistence
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
SummaryThe OpenC3 password change functionality allows a user to change their password without providing the old password, by accepting a valid session token instead. In assumed breach scenarios, this behaviour can be exploited by an attacker who has already obtained a valid session token, to gain persistence in hijacked account (including admin) and prevent legitimate users from accessing the account. DetailsThe design flaw in authentication model (authentication.rb) allows for interchangeable use of password and session tokens for user authentication As old tokens are not revoked upon password reset, an attacker who has obtained a valid session token can continue to authenticate and change the account’s password even after the victim resets it, thereby maintaining persistent control over the compromised account. PoC
ImpactPersistence of an attacker who obtained valid session token and preventing legitimate users from account access Affected versions
5.0.10
5.0.11
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.10.0
5.10.1
5.11.0
5.11.1
+ 71 more Show less
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.2.0
5.20.0
5.3.0
5.4.0
5.4.1
5.4.2
5.4.3.pre.beta0
5.5.0
5.5.0.pre.beta0
5.5.1
5.5.2
5.5.2.pre.beta0
5.6.0
5.6.1
5.7.0
5.7.2
5.8.0
5.8.1
5.9.0
5.9.1
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
7.0.0
7.0.0.pre.rc1
7.0.0.pre.rc2
7.0.0.pre.rc3
7.0.1
7.1.0
7.1.1
7.2.0
7.2.1
7.3.0
Fixed in
6.10.5
7.0.0-rc3
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2025-68271
GHSA-w757-4qv9-mghp
Jan 13, 2026
openc3-api Vulnerable to Unauthenticated Remote Code Execution
10.0
/ 10
Critical
Network
Low
None
None
Changed
High
High
High
SummaryOpenC3 COSMOS contains a critical remote code execution vulnerability reachable through the JSON-RPC API. When a JSON-RPC request uses the string form of certain APIs, attacker-controlled parameter text is parsed into values using String#convert_to_value. For array-like inputs, convert_to_value executes eval(). Because the cmd code path parses the command string before calling authorize(), an unauthenticated attacker can trigger Ruby code execution even though the request ultimately fails authorization (401). Affected versions
5.0.10
5.0.11
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.10.0
5.10.1
5.11.0
5.11.1
+ 58 more Show less
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.2.0
5.20.0
5.3.0
5.4.0
5.4.1
5.4.2
5.4.3.pre.beta0
5.5.0
5.5.0.pre.beta0
5.5.1
5.5.2
5.5.2.pre.beta0
5.6.0
5.6.1
5.7.0
5.7.2
5.8.0
5.8.1
5.9.0
5.9.1
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
Fixed in
6.10.2
References
Updated Feb 03, 2026 · Source: OSV.dev |
6.1.0
minor
Dependencies (53)
+ 45 more
Changelog
Compare changes
|
|
6.0.2
patch
5 CVEs
CVE-2026-42088
GHSA-2wvh-87g2-89hr
PYSEC-2026-2245
Apr 23, 2026
OpenC3 COSMOS: Permissions Bypass Provides User Access to Unassigned Administrative Actions via Script Runner Tool
9.6
/ 10
Critical
Network
Low
Low
None
Changed
High
High
None
Vulnerability Type: Execution with Unnecessary Privileges Attack type: Authenticated remote Impact: Data disclosure/manipulation, privilege escalation Affected components: The following docker images: • Openc3inc/openc3-COSMOS-script-runner-api The Script Runner widget allows users to execute Python and Ruby scripts directly from the openc3-COSMOS-script-runner-api container. Because all the docker containers share a network, users can execute specially crafted scripts to bypass the API permissions check and perform administrative actions, including reading and modifying data inside the Redis database, which can be used to read secrets and change COSMOS settings, as well as read and write to the buckets service, which holds configuration, log, and plugin files. These actions are normally only available from the Admin Console or with administrative privileges. Any user with permission to create and run scripts can connect to any service in the docker network. Figure 1: Environment variables, including Redis credentials, found in the Script Runner container A Ruby script is used to expose the Redis username, password, hostname, and port. These credentials might also be found from the source code or through a brute-force attack. Figure 2: A Python script is used to add data to Redis and retrieve the new data
A Python script is then used to create a new entry in the Redis database called Figure 3: The new data found in the Redis database
The new entry was successfully added to the Redis database, as is confirmed by using Figure 4: Uploading file to change the plugin store URL setting Figure 5: The URL file was successfully changed Steps To Reproduce
Recommendations• Limit the permissions of the script runner API to prevent lower level users from performing administrative actions Affected versions
5.0.10
5.0.11
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.10.0
5.10.1
5.11.0
5.11.1
+ 63 more Show less
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.2.0
5.20.0
5.3.0
5.4.0
5.4.1
5.4.2
5.4.3.pre.beta0
5.5.0
5.5.0.pre.beta0
5.5.1
5.5.2
5.5.2.pre.beta0
5.6.0
5.6.1
5.7.0
5.7.2
5.8.0
5.8.1
5.9.0
5.9.1
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.10.5
6.10.6
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
Fixed in
7.0.0-rc3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-42086
GHSA-ffq5-qpvf-xq7x
PYSEC-2026-105
Apr 22, 2026
OpenC3 COSMOS is Vulnerable to Self-XSS Through the Command Sender
4.6
/ 10
Medium
Network
Low
Low
Required
Unchanged
Low
Low
None
SummaryThe Command Sender UI uses an unsafe DetailsThe unsafe PoC
Below example uses ImpactLocal JavaScript execution in the user's browser Affected versions
5.0.10
5.0.11
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.10.0
5.10.1
5.11.0
5.11.1
+ 66 more Show less
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.2.0
5.20.0
5.3.0
5.4.0
5.4.1
5.4.2
5.4.3.pre.beta0
5.5.0
5.5.0.pre.beta0
5.5.1
5.5.2
5.5.2.pre.beta0
5.6.0
5.6.1
5.7.0
5.7.2
5.8.0
5.8.1
5.9.0
5.9.1
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.10.5
6.10.6
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
7.0.0.pre.rc1
7.0.0.pre.rc2
7.0.0.pre.rc3
Fixed in
7.0.0
References
Updated May 29, 2026 · Source: OSV.dev
CVE-2026-42085
GHSA-4jvx-93h3-f45h
PYSEC-2026-2243
Apr 22, 2026
OpenC3 COSMOS allows arbitrary writes to plugins directory via path-traversed config filenames
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
None
SummaryOpenC3 COSMOS contains a design flaw in the DetailsIn function PoC
ImpactModifying the data of other plugins Affected versions
5.0.10
5.0.11
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.10.0
5.10.1
5.11.0
5.11.1
+ 71 more Show less
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.2.0
5.20.0
5.3.0
5.4.0
5.4.1
5.4.2
5.4.3.pre.beta0
5.5.0
5.5.0.pre.beta0
5.5.1
5.5.2
5.5.2.pre.beta0
5.6.0
5.6.1
5.7.0
5.7.2
5.8.0
5.8.1
5.9.0
5.9.1
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
7.0.0
7.0.0.pre.rc1
7.0.0.pre.rc2
7.0.0.pre.rc3
7.0.1
7.1.0
7.1.1
7.2.0
7.2.1
7.3.0
Fixed in
6.10.5
7.0.0-rc3
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-42084
GHSA-wgx6-g857-jjf7
PYSEC-2026-2242
Apr 22, 2026
OpenC3 COSMOS: Hijacked session token can be used to reset password for persistence
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
SummaryThe OpenC3 password change functionality allows a user to change their password without providing the old password, by accepting a valid session token instead. In assumed breach scenarios, this behaviour can be exploited by an attacker who has already obtained a valid session token, to gain persistence in hijacked account (including admin) and prevent legitimate users from accessing the account. DetailsThe design flaw in authentication model (authentication.rb) allows for interchangeable use of password and session tokens for user authentication As old tokens are not revoked upon password reset, an attacker who has obtained a valid session token can continue to authenticate and change the account’s password even after the victim resets it, thereby maintaining persistent control over the compromised account. PoC
ImpactPersistence of an attacker who obtained valid session token and preventing legitimate users from account access Affected versions
5.0.10
5.0.11
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.10.0
5.10.1
5.11.0
5.11.1
+ 71 more Show less
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.2.0
5.20.0
5.3.0
5.4.0
5.4.1
5.4.2
5.4.3.pre.beta0
5.5.0
5.5.0.pre.beta0
5.5.1
5.5.2
5.5.2.pre.beta0
5.6.0
5.6.1
5.7.0
5.7.2
5.8.0
5.8.1
5.9.0
5.9.1
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
7.0.0
7.0.0.pre.rc1
7.0.0.pre.rc2
7.0.0.pre.rc3
7.0.1
7.1.0
7.1.1
7.2.0
7.2.1
7.3.0
Fixed in
6.10.5
7.0.0-rc3
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2025-68271
GHSA-w757-4qv9-mghp
Jan 13, 2026
openc3-api Vulnerable to Unauthenticated Remote Code Execution
10.0
/ 10
Critical
Network
Low
None
None
Changed
High
High
High
SummaryOpenC3 COSMOS contains a critical remote code execution vulnerability reachable through the JSON-RPC API. When a JSON-RPC request uses the string form of certain APIs, attacker-controlled parameter text is parsed into values using String#convert_to_value. For array-like inputs, convert_to_value executes eval(). Because the cmd code path parses the command string before calling authorize(), an unauthenticated attacker can trigger Ruby code execution even though the request ultimately fails authorization (401). Affected versions
5.0.10
5.0.11
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.10.0
5.10.1
5.11.0
5.11.1
+ 58 more Show less
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.2.0
5.20.0
5.3.0
5.4.0
5.4.1
5.4.2
5.4.3.pre.beta0
5.5.0
5.5.0.pre.beta0
5.5.1
5.5.2
5.5.2.pre.beta0
5.6.0
5.6.1
5.7.0
5.7.2
5.8.0
5.8.1
5.9.0
5.9.1
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
Fixed in
6.10.2
References
Updated Feb 03, 2026 · Source: OSV.dev |
6.0.2
patch
Dependencies (53)
+ 45 more
Changelog
Compare changes
|
|
6.0.1
patch
5 CVEs
CVE-2026-42088
GHSA-2wvh-87g2-89hr
PYSEC-2026-2245
Apr 23, 2026
OpenC3 COSMOS: Permissions Bypass Provides User Access to Unassigned Administrative Actions via Script Runner Tool
9.6
/ 10
Critical
Network
Low
Low
None
Changed
High
High
None
Vulnerability Type: Execution with Unnecessary Privileges Attack type: Authenticated remote Impact: Data disclosure/manipulation, privilege escalation Affected components: The following docker images: • Openc3inc/openc3-COSMOS-script-runner-api The Script Runner widget allows users to execute Python and Ruby scripts directly from the openc3-COSMOS-script-runner-api container. Because all the docker containers share a network, users can execute specially crafted scripts to bypass the API permissions check and perform administrative actions, including reading and modifying data inside the Redis database, which can be used to read secrets and change COSMOS settings, as well as read and write to the buckets service, which holds configuration, log, and plugin files. These actions are normally only available from the Admin Console or with administrative privileges. Any user with permission to create and run scripts can connect to any service in the docker network. Figure 1: Environment variables, including Redis credentials, found in the Script Runner container A Ruby script is used to expose the Redis username, password, hostname, and port. These credentials might also be found from the source code or through a brute-force attack. Figure 2: A Python script is used to add data to Redis and retrieve the new data
A Python script is then used to create a new entry in the Redis database called Figure 3: The new data found in the Redis database
The new entry was successfully added to the Redis database, as is confirmed by using Figure 4: Uploading file to change the plugin store URL setting Figure 5: The URL file was successfully changed Steps To Reproduce
Recommendations• Limit the permissions of the script runner API to prevent lower level users from performing administrative actions Affected versions
5.0.10
5.0.11
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.10.0
5.10.1
5.11.0
5.11.1
+ 63 more Show less
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.2.0
5.20.0
5.3.0
5.4.0
5.4.1
5.4.2
5.4.3.pre.beta0
5.5.0
5.5.0.pre.beta0
5.5.1
5.5.2
5.5.2.pre.beta0
5.6.0
5.6.1
5.7.0
5.7.2
5.8.0
5.8.1
5.9.0
5.9.1
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.10.5
6.10.6
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
Fixed in
7.0.0-rc3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-42086
GHSA-ffq5-qpvf-xq7x
PYSEC-2026-105
Apr 22, 2026
OpenC3 COSMOS is Vulnerable to Self-XSS Through the Command Sender
4.6
/ 10
Medium
Network
Low
Low
Required
Unchanged
Low
Low
None
SummaryThe Command Sender UI uses an unsafe DetailsThe unsafe PoC
Below example uses ImpactLocal JavaScript execution in the user's browser Affected versions
5.0.10
5.0.11
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.10.0
5.10.1
5.11.0
5.11.1
+ 66 more Show less
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.2.0
5.20.0
5.3.0
5.4.0
5.4.1
5.4.2
5.4.3.pre.beta0
5.5.0
5.5.0.pre.beta0
5.5.1
5.5.2
5.5.2.pre.beta0
5.6.0
5.6.1
5.7.0
5.7.2
5.8.0
5.8.1
5.9.0
5.9.1
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.10.5
6.10.6
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
7.0.0.pre.rc1
7.0.0.pre.rc2
7.0.0.pre.rc3
Fixed in
7.0.0
References
Updated May 29, 2026 · Source: OSV.dev
CVE-2026-42085
GHSA-4jvx-93h3-f45h
PYSEC-2026-2243
Apr 22, 2026
OpenC3 COSMOS allows arbitrary writes to plugins directory via path-traversed config filenames
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
None
SummaryOpenC3 COSMOS contains a design flaw in the DetailsIn function PoC
ImpactModifying the data of other plugins Affected versions
5.0.10
5.0.11
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.10.0
5.10.1
5.11.0
5.11.1
+ 71 more Show less
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.2.0
5.20.0
5.3.0
5.4.0
5.4.1
5.4.2
5.4.3.pre.beta0
5.5.0
5.5.0.pre.beta0
5.5.1
5.5.2
5.5.2.pre.beta0
5.6.0
5.6.1
5.7.0
5.7.2
5.8.0
5.8.1
5.9.0
5.9.1
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
7.0.0
7.0.0.pre.rc1
7.0.0.pre.rc2
7.0.0.pre.rc3
7.0.1
7.1.0
7.1.1
7.2.0
7.2.1
7.3.0
Fixed in
6.10.5
7.0.0-rc3
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-42084
GHSA-wgx6-g857-jjf7
PYSEC-2026-2242
Apr 22, 2026
OpenC3 COSMOS: Hijacked session token can be used to reset password for persistence
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
SummaryThe OpenC3 password change functionality allows a user to change their password without providing the old password, by accepting a valid session token instead. In assumed breach scenarios, this behaviour can be exploited by an attacker who has already obtained a valid session token, to gain persistence in hijacked account (including admin) and prevent legitimate users from accessing the account. DetailsThe design flaw in authentication model (authentication.rb) allows for interchangeable use of password and session tokens for user authentication As old tokens are not revoked upon password reset, an attacker who has obtained a valid session token can continue to authenticate and change the account’s password even after the victim resets it, thereby maintaining persistent control over the compromised account. PoC
ImpactPersistence of an attacker who obtained valid session token and preventing legitimate users from account access Affected versions
5.0.10
5.0.11
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.10.0
5.10.1
5.11.0
5.11.1
+ 71 more Show less
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.2.0
5.20.0
5.3.0
5.4.0
5.4.1
5.4.2
5.4.3.pre.beta0
5.5.0
5.5.0.pre.beta0
5.5.1
5.5.2
5.5.2.pre.beta0
5.6.0
5.6.1
5.7.0
5.7.2
5.8.0
5.8.1
5.9.0
5.9.1
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
7.0.0
7.0.0.pre.rc1
7.0.0.pre.rc2
7.0.0.pre.rc3
7.0.1
7.1.0
7.1.1
7.2.0
7.2.1
7.3.0
Fixed in
6.10.5
7.0.0-rc3
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2025-68271
GHSA-w757-4qv9-mghp
Jan 13, 2026
openc3-api Vulnerable to Unauthenticated Remote Code Execution
10.0
/ 10
Critical
Network
Low
None
None
Changed
High
High
High
SummaryOpenC3 COSMOS contains a critical remote code execution vulnerability reachable through the JSON-RPC API. When a JSON-RPC request uses the string form of certain APIs, attacker-controlled parameter text is parsed into values using String#convert_to_value. For array-like inputs, convert_to_value executes eval(). Because the cmd code path parses the command string before calling authorize(), an unauthenticated attacker can trigger Ruby code execution even though the request ultimately fails authorization (401). Affected versions
5.0.10
5.0.11
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.10.0
5.10.1
5.11.0
5.11.1
+ 58 more Show less
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.2.0
5.20.0
5.3.0
5.4.0
5.4.1
5.4.2
5.4.3.pre.beta0
5.5.0
5.5.0.pre.beta0
5.5.1
5.5.2
5.5.2.pre.beta0
5.6.0
5.6.1
5.7.0
5.7.2
5.8.0
5.8.1
5.9.0
5.9.1
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
Fixed in
6.10.2
References
Updated Feb 03, 2026 · Source: OSV.dev |
6.0.1
patch
Dependencies (53)
+ 45 more
Changelog
Compare changes
|
|
6.0.0
major
5 CVEs
CVE-2026-42088
GHSA-2wvh-87g2-89hr
PYSEC-2026-2245
Apr 23, 2026
OpenC3 COSMOS: Permissions Bypass Provides User Access to Unassigned Administrative Actions via Script Runner Tool
9.6
/ 10
Critical
Network
Low
Low
None
Changed
High
High
None
Vulnerability Type: Execution with Unnecessary Privileges Attack type: Authenticated remote Impact: Data disclosure/manipulation, privilege escalation Affected components: The following docker images: • Openc3inc/openc3-COSMOS-script-runner-api The Script Runner widget allows users to execute Python and Ruby scripts directly from the openc3-COSMOS-script-runner-api container. Because all the docker containers share a network, users can execute specially crafted scripts to bypass the API permissions check and perform administrative actions, including reading and modifying data inside the Redis database, which can be used to read secrets and change COSMOS settings, as well as read and write to the buckets service, which holds configuration, log, and plugin files. These actions are normally only available from the Admin Console or with administrative privileges. Any user with permission to create and run scripts can connect to any service in the docker network. Figure 1: Environment variables, including Redis credentials, found in the Script Runner container A Ruby script is used to expose the Redis username, password, hostname, and port. These credentials might also be found from the source code or through a brute-force attack. Figure 2: A Python script is used to add data to Redis and retrieve the new data
A Python script is then used to create a new entry in the Redis database called Figure 3: The new data found in the Redis database
The new entry was successfully added to the Redis database, as is confirmed by using Figure 4: Uploading file to change the plugin store URL setting Figure 5: The URL file was successfully changed Steps To Reproduce
Recommendations• Limit the permissions of the script runner API to prevent lower level users from performing administrative actions Affected versions
5.0.10
5.0.11
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.10.0
5.10.1
5.11.0
5.11.1
+ 63 more Show less
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.2.0
5.20.0
5.3.0
5.4.0
5.4.1
5.4.2
5.4.3.pre.beta0
5.5.0
5.5.0.pre.beta0
5.5.1
5.5.2
5.5.2.pre.beta0
5.6.0
5.6.1
5.7.0
5.7.2
5.8.0
5.8.1
5.9.0
5.9.1
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.10.5
6.10.6
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
Fixed in
7.0.0-rc3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-42086
GHSA-ffq5-qpvf-xq7x
PYSEC-2026-105
Apr 22, 2026
OpenC3 COSMOS is Vulnerable to Self-XSS Through the Command Sender
4.6
/ 10
Medium
Network
Low
Low
Required
Unchanged
Low
Low
None
SummaryThe Command Sender UI uses an unsafe DetailsThe unsafe PoC
Below example uses ImpactLocal JavaScript execution in the user's browser Affected versions
5.0.10
5.0.11
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.10.0
5.10.1
5.11.0
5.11.1
+ 66 more Show less
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.2.0
5.20.0
5.3.0
5.4.0
5.4.1
5.4.2
5.4.3.pre.beta0
5.5.0
5.5.0.pre.beta0
5.5.1
5.5.2
5.5.2.pre.beta0
5.6.0
5.6.1
5.7.0
5.7.2
5.8.0
5.8.1
5.9.0
5.9.1
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.10.5
6.10.6
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
7.0.0.pre.rc1
7.0.0.pre.rc2
7.0.0.pre.rc3
Fixed in
7.0.0
References
Updated May 29, 2026 · Source: OSV.dev
CVE-2026-42085
GHSA-4jvx-93h3-f45h
PYSEC-2026-2243
Apr 22, 2026
OpenC3 COSMOS allows arbitrary writes to plugins directory via path-traversed config filenames
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
None
SummaryOpenC3 COSMOS contains a design flaw in the DetailsIn function PoC
ImpactModifying the data of other plugins Affected versions
5.0.10
5.0.11
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.10.0
5.10.1
5.11.0
5.11.1
+ 71 more Show less
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.2.0
5.20.0
5.3.0
5.4.0
5.4.1
5.4.2
5.4.3.pre.beta0
5.5.0
5.5.0.pre.beta0
5.5.1
5.5.2
5.5.2.pre.beta0
5.6.0
5.6.1
5.7.0
5.7.2
5.8.0
5.8.1
5.9.0
5.9.1
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
7.0.0
7.0.0.pre.rc1
7.0.0.pre.rc2
7.0.0.pre.rc3
7.0.1
7.1.0
7.1.1
7.2.0
7.2.1
7.3.0
Fixed in
6.10.5
7.0.0-rc3
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-42084
GHSA-wgx6-g857-jjf7
PYSEC-2026-2242
Apr 22, 2026
OpenC3 COSMOS: Hijacked session token can be used to reset password for persistence
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
SummaryThe OpenC3 password change functionality allows a user to change their password without providing the old password, by accepting a valid session token instead. In assumed breach scenarios, this behaviour can be exploited by an attacker who has already obtained a valid session token, to gain persistence in hijacked account (including admin) and prevent legitimate users from accessing the account. DetailsThe design flaw in authentication model (authentication.rb) allows for interchangeable use of password and session tokens for user authentication As old tokens are not revoked upon password reset, an attacker who has obtained a valid session token can continue to authenticate and change the account’s password even after the victim resets it, thereby maintaining persistent control over the compromised account. PoC
ImpactPersistence of an attacker who obtained valid session token and preventing legitimate users from account access Affected versions
5.0.10
5.0.11
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.10.0
5.10.1
5.11.0
5.11.1
+ 71 more Show less
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.2.0
5.20.0
5.3.0
5.4.0
5.4.1
5.4.2
5.4.3.pre.beta0
5.5.0
5.5.0.pre.beta0
5.5.1
5.5.2
5.5.2.pre.beta0
5.6.0
5.6.1
5.7.0
5.7.2
5.8.0
5.8.1
5.9.0
5.9.1
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
7.0.0
7.0.0.pre.rc1
7.0.0.pre.rc2
7.0.0.pre.rc3
7.0.1
7.1.0
7.1.1
7.2.0
7.2.1
7.3.0
Fixed in
6.10.5
7.0.0-rc3
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2025-68271
GHSA-w757-4qv9-mghp
Jan 13, 2026
openc3-api Vulnerable to Unauthenticated Remote Code Execution
10.0
/ 10
Critical
Network
Low
None
None
Changed
High
High
High
SummaryOpenC3 COSMOS contains a critical remote code execution vulnerability reachable through the JSON-RPC API. When a JSON-RPC request uses the string form of certain APIs, attacker-controlled parameter text is parsed into values using String#convert_to_value. For array-like inputs, convert_to_value executes eval(). Because the cmd code path parses the command string before calling authorize(), an unauthenticated attacker can trigger Ruby code execution even though the request ultimately fails authorization (401). Affected versions
5.0.10
5.0.11
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.10.0
5.10.1
5.11.0
5.11.1
+ 58 more Show less
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.2.0
5.20.0
5.3.0
5.4.0
5.4.1
5.4.2
5.4.3.pre.beta0
5.5.0
5.5.0.pre.beta0
5.5.1
5.5.2
5.5.2.pre.beta0
5.6.0
5.6.1
5.7.0
5.7.2
5.8.0
5.8.1
5.9.0
5.9.1
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
Fixed in
6.10.2
References
Updated Feb 03, 2026 · Source: OSV.dev |
6.0.0
major
Dependencies (53)
+ 45 more
Changelog
Compare changes
|
|
5.20.0
minor
5 CVEs
CVE-2026-42088
GHSA-2wvh-87g2-89hr
PYSEC-2026-2245
Apr 23, 2026
OpenC3 COSMOS: Permissions Bypass Provides User Access to Unassigned Administrative Actions via Script Runner Tool
9.6
/ 10
Critical
Network
Low
Low
None
Changed
High
High
None
Vulnerability Type: Execution with Unnecessary Privileges Attack type: Authenticated remote Impact: Data disclosure/manipulation, privilege escalation Affected components: The following docker images: • Openc3inc/openc3-COSMOS-script-runner-api The Script Runner widget allows users to execute Python and Ruby scripts directly from the openc3-COSMOS-script-runner-api container. Because all the docker containers share a network, users can execute specially crafted scripts to bypass the API permissions check and perform administrative actions, including reading and modifying data inside the Redis database, which can be used to read secrets and change COSMOS settings, as well as read and write to the buckets service, which holds configuration, log, and plugin files. These actions are normally only available from the Admin Console or with administrative privileges. Any user with permission to create and run scripts can connect to any service in the docker network. Figure 1: Environment variables, including Redis credentials, found in the Script Runner container A Ruby script is used to expose the Redis username, password, hostname, and port. These credentials might also be found from the source code or through a brute-force attack. Figure 2: A Python script is used to add data to Redis and retrieve the new data
A Python script is then used to create a new entry in the Redis database called Figure 3: The new data found in the Redis database
The new entry was successfully added to the Redis database, as is confirmed by using Figure 4: Uploading file to change the plugin store URL setting Figure 5: The URL file was successfully changed Steps To Reproduce
Recommendations• Limit the permissions of the script runner API to prevent lower level users from performing administrative actions Affected versions
5.0.10
5.0.11
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.10.0
5.10.1
5.11.0
5.11.1
+ 63 more Show less
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.2.0
5.20.0
5.3.0
5.4.0
5.4.1
5.4.2
5.4.3.pre.beta0
5.5.0
5.5.0.pre.beta0
5.5.1
5.5.2
5.5.2.pre.beta0
5.6.0
5.6.1
5.7.0
5.7.2
5.8.0
5.8.1
5.9.0
5.9.1
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.10.5
6.10.6
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
Fixed in
7.0.0-rc3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-42086
GHSA-ffq5-qpvf-xq7x
PYSEC-2026-105
Apr 22, 2026
OpenC3 COSMOS is Vulnerable to Self-XSS Through the Command Sender
4.6
/ 10
Medium
Network
Low
Low
Required
Unchanged
Low
Low
None
SummaryThe Command Sender UI uses an unsafe DetailsThe unsafe PoC
Below example uses ImpactLocal JavaScript execution in the user's browser Affected versions
5.0.10
5.0.11
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.10.0
5.10.1
5.11.0
5.11.1
+ 66 more Show less
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.2.0
5.20.0
5.3.0
5.4.0
5.4.1
5.4.2
5.4.3.pre.beta0
5.5.0
5.5.0.pre.beta0
5.5.1
5.5.2
5.5.2.pre.beta0
5.6.0
5.6.1
5.7.0
5.7.2
5.8.0
5.8.1
5.9.0
5.9.1
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.10.5
6.10.6
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
7.0.0.pre.rc1
7.0.0.pre.rc2
7.0.0.pre.rc3
Fixed in
7.0.0
References
Updated May 29, 2026 · Source: OSV.dev
CVE-2026-42085
GHSA-4jvx-93h3-f45h
PYSEC-2026-2243
Apr 22, 2026
OpenC3 COSMOS allows arbitrary writes to plugins directory via path-traversed config filenames
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
None
SummaryOpenC3 COSMOS contains a design flaw in the DetailsIn function PoC
ImpactModifying the data of other plugins Affected versions
5.0.10
5.0.11
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.10.0
5.10.1
5.11.0
5.11.1
+ 71 more Show less
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.2.0
5.20.0
5.3.0
5.4.0
5.4.1
5.4.2
5.4.3.pre.beta0
5.5.0
5.5.0.pre.beta0
5.5.1
5.5.2
5.5.2.pre.beta0
5.6.0
5.6.1
5.7.0
5.7.2
5.8.0
5.8.1
5.9.0
5.9.1
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
7.0.0
7.0.0.pre.rc1
7.0.0.pre.rc2
7.0.0.pre.rc3
7.0.1
7.1.0
7.1.1
7.2.0
7.2.1
7.3.0
Fixed in
6.10.5
7.0.0-rc3
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-42084
GHSA-wgx6-g857-jjf7
PYSEC-2026-2242
Apr 22, 2026
OpenC3 COSMOS: Hijacked session token can be used to reset password for persistence
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
SummaryThe OpenC3 password change functionality allows a user to change their password without providing the old password, by accepting a valid session token instead. In assumed breach scenarios, this behaviour can be exploited by an attacker who has already obtained a valid session token, to gain persistence in hijacked account (including admin) and prevent legitimate users from accessing the account. DetailsThe design flaw in authentication model (authentication.rb) allows for interchangeable use of password and session tokens for user authentication As old tokens are not revoked upon password reset, an attacker who has obtained a valid session token can continue to authenticate and change the account’s password even after the victim resets it, thereby maintaining persistent control over the compromised account. PoC
ImpactPersistence of an attacker who obtained valid session token and preventing legitimate users from account access Affected versions
5.0.10
5.0.11
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.10.0
5.10.1
5.11.0
5.11.1
+ 71 more Show less
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.2.0
5.20.0
5.3.0
5.4.0
5.4.1
5.4.2
5.4.3.pre.beta0
5.5.0
5.5.0.pre.beta0
5.5.1
5.5.2
5.5.2.pre.beta0
5.6.0
5.6.1
5.7.0
5.7.2
5.8.0
5.8.1
5.9.0
5.9.1
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
7.0.0
7.0.0.pre.rc1
7.0.0.pre.rc2
7.0.0.pre.rc3
7.0.1
7.1.0
7.1.1
7.2.0
7.2.1
7.3.0
Fixed in
6.10.5
7.0.0-rc3
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2025-68271
GHSA-w757-4qv9-mghp
Jan 13, 2026
openc3-api Vulnerable to Unauthenticated Remote Code Execution
10.0
/ 10
Critical
Network
Low
None
None
Changed
High
High
High
SummaryOpenC3 COSMOS contains a critical remote code execution vulnerability reachable through the JSON-RPC API. When a JSON-RPC request uses the string form of certain APIs, attacker-controlled parameter text is parsed into values using String#convert_to_value. For array-like inputs, convert_to_value executes eval(). Because the cmd code path parses the command string before calling authorize(), an unauthenticated attacker can trigger Ruby code execution even though the request ultimately fails authorization (401). Affected versions
5.0.10
5.0.11
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.10.0
5.10.1
5.11.0
5.11.1
+ 58 more Show less
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.2.0
5.20.0
5.3.0
5.4.0
5.4.1
5.4.2
5.4.3.pre.beta0
5.5.0
5.5.0.pre.beta0
5.5.1
5.5.2
5.5.2.pre.beta0
5.6.0
5.6.1
5.7.0
5.7.2
5.8.0
5.8.1
5.9.0
5.9.1
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
Fixed in
6.10.2
References
Updated Feb 03, 2026 · Source: OSV.dev |
5.20.0
minor
Dependencies (54)
+ 46 more
Changelog
Compare changes
|
|
5.19.0
minor
5 CVEs
CVE-2026-42088
GHSA-2wvh-87g2-89hr
PYSEC-2026-2245
Apr 23, 2026
OpenC3 COSMOS: Permissions Bypass Provides User Access to Unassigned Administrative Actions via Script Runner Tool
9.6
/ 10
Critical
Network
Low
Low
None
Changed
High
High
None
Vulnerability Type: Execution with Unnecessary Privileges Attack type: Authenticated remote Impact: Data disclosure/manipulation, privilege escalation Affected components: The following docker images: • Openc3inc/openc3-COSMOS-script-runner-api The Script Runner widget allows users to execute Python and Ruby scripts directly from the openc3-COSMOS-script-runner-api container. Because all the docker containers share a network, users can execute specially crafted scripts to bypass the API permissions check and perform administrative actions, including reading and modifying data inside the Redis database, which can be used to read secrets and change COSMOS settings, as well as read and write to the buckets service, which holds configuration, log, and plugin files. These actions are normally only available from the Admin Console or with administrative privileges. Any user with permission to create and run scripts can connect to any service in the docker network. Figure 1: Environment variables, including Redis credentials, found in the Script Runner container A Ruby script is used to expose the Redis username, password, hostname, and port. These credentials might also be found from the source code or through a brute-force attack. Figure 2: A Python script is used to add data to Redis and retrieve the new data
A Python script is then used to create a new entry in the Redis database called Figure 3: The new data found in the Redis database
The new entry was successfully added to the Redis database, as is confirmed by using Figure 4: Uploading file to change the plugin store URL setting Figure 5: The URL file was successfully changed Steps To Reproduce
Recommendations• Limit the permissions of the script runner API to prevent lower level users from performing administrative actions Affected versions
5.0.10
5.0.11
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.10.0
5.10.1
5.11.0
5.11.1
+ 63 more Show less
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.2.0
5.20.0
5.3.0
5.4.0
5.4.1
5.4.2
5.4.3.pre.beta0
5.5.0
5.5.0.pre.beta0
5.5.1
5.5.2
5.5.2.pre.beta0
5.6.0
5.6.1
5.7.0
5.7.2
5.8.0
5.8.1
5.9.0
5.9.1
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.10.5
6.10.6
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
Fixed in
7.0.0-rc3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-42086
GHSA-ffq5-qpvf-xq7x
PYSEC-2026-105
Apr 22, 2026
OpenC3 COSMOS is Vulnerable to Self-XSS Through the Command Sender
4.6
/ 10
Medium
Network
Low
Low
Required
Unchanged
Low
Low
None
SummaryThe Command Sender UI uses an unsafe DetailsThe unsafe PoC
Below example uses ImpactLocal JavaScript execution in the user's browser Affected versions
5.0.10
5.0.11
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.10.0
5.10.1
5.11.0
5.11.1
+ 66 more Show less
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.2.0
5.20.0
5.3.0
5.4.0
5.4.1
5.4.2
5.4.3.pre.beta0
5.5.0
5.5.0.pre.beta0
5.5.1
5.5.2
5.5.2.pre.beta0
5.6.0
5.6.1
5.7.0
5.7.2
5.8.0
5.8.1
5.9.0
5.9.1
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.10.5
6.10.6
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
7.0.0.pre.rc1
7.0.0.pre.rc2
7.0.0.pre.rc3
Fixed in
7.0.0
References
Updated May 29, 2026 · Source: OSV.dev
CVE-2026-42085
GHSA-4jvx-93h3-f45h
PYSEC-2026-2243
Apr 22, 2026
OpenC3 COSMOS allows arbitrary writes to plugins directory via path-traversed config filenames
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
None
SummaryOpenC3 COSMOS contains a design flaw in the DetailsIn function PoC
ImpactModifying the data of other plugins Affected versions
5.0.10
5.0.11
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.10.0
5.10.1
5.11.0
5.11.1
+ 71 more Show less
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.2.0
5.20.0
5.3.0
5.4.0
5.4.1
5.4.2
5.4.3.pre.beta0
5.5.0
5.5.0.pre.beta0
5.5.1
5.5.2
5.5.2.pre.beta0
5.6.0
5.6.1
5.7.0
5.7.2
5.8.0
5.8.1
5.9.0
5.9.1
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
7.0.0
7.0.0.pre.rc1
7.0.0.pre.rc2
7.0.0.pre.rc3
7.0.1
7.1.0
7.1.1
7.2.0
7.2.1
7.3.0
Fixed in
6.10.5
7.0.0-rc3
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-42084
GHSA-wgx6-g857-jjf7
PYSEC-2026-2242
Apr 22, 2026
OpenC3 COSMOS: Hijacked session token can be used to reset password for persistence
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
SummaryThe OpenC3 password change functionality allows a user to change their password without providing the old password, by accepting a valid session token instead. In assumed breach scenarios, this behaviour can be exploited by an attacker who has already obtained a valid session token, to gain persistence in hijacked account (including admin) and prevent legitimate users from accessing the account. DetailsThe design flaw in authentication model (authentication.rb) allows for interchangeable use of password and session tokens for user authentication As old tokens are not revoked upon password reset, an attacker who has obtained a valid session token can continue to authenticate and change the account’s password even after the victim resets it, thereby maintaining persistent control over the compromised account. PoC
ImpactPersistence of an attacker who obtained valid session token and preventing legitimate users from account access Affected versions
5.0.10
5.0.11
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.10.0
5.10.1
5.11.0
5.11.1
+ 71 more Show less
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.2.0
5.20.0
5.3.0
5.4.0
5.4.1
5.4.2
5.4.3.pre.beta0
5.5.0
5.5.0.pre.beta0
5.5.1
5.5.2
5.5.2.pre.beta0
5.6.0
5.6.1
5.7.0
5.7.2
5.8.0
5.8.1
5.9.0
5.9.1
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
7.0.0
7.0.0.pre.rc1
7.0.0.pre.rc2
7.0.0.pre.rc3
7.0.1
7.1.0
7.1.1
7.2.0
7.2.1
7.3.0
Fixed in
6.10.5
7.0.0-rc3
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2025-68271
GHSA-w757-4qv9-mghp
Jan 13, 2026
openc3-api Vulnerable to Unauthenticated Remote Code Execution
10.0
/ 10
Critical
Network
Low
None
None
Changed
High
High
High
SummaryOpenC3 COSMOS contains a critical remote code execution vulnerability reachable through the JSON-RPC API. When a JSON-RPC request uses the string form of certain APIs, attacker-controlled parameter text is parsed into values using String#convert_to_value. For array-like inputs, convert_to_value executes eval(). Because the cmd code path parses the command string before calling authorize(), an unauthenticated attacker can trigger Ruby code execution even though the request ultimately fails authorization (401). Affected versions
5.0.10
5.0.11
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.10.0
5.10.1
5.11.0
5.11.1
+ 58 more Show less
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.2.0
5.20.0
5.3.0
5.4.0
5.4.1
5.4.2
5.4.3.pre.beta0
5.5.0
5.5.0.pre.beta0
5.5.1
5.5.2
5.5.2.pre.beta0
5.6.0
5.6.1
5.7.0
5.7.2
5.8.0
5.8.1
5.9.0
5.9.1
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
Fixed in
6.10.2
References
Updated Feb 03, 2026 · Source: OSV.dev |
5.19.0
minor
Dependencies (53)
+ 45 more
Changelog
Compare changes
|
|
5.18.0
minor
8 CVEs
CVE-2026-42088
GHSA-2wvh-87g2-89hr
PYSEC-2026-2245
Apr 23, 2026
OpenC3 COSMOS: Permissions Bypass Provides User Access to Unassigned Administrative Actions via Script Runner Tool
9.6
/ 10
Critical
Network
Low
Low
None
Changed
High
High
None
Vulnerability Type: Execution with Unnecessary Privileges Attack type: Authenticated remote Impact: Data disclosure/manipulation, privilege escalation Affected components: The following docker images: • Openc3inc/openc3-COSMOS-script-runner-api The Script Runner widget allows users to execute Python and Ruby scripts directly from the openc3-COSMOS-script-runner-api container. Because all the docker containers share a network, users can execute specially crafted scripts to bypass the API permissions check and perform administrative actions, including reading and modifying data inside the Redis database, which can be used to read secrets and change COSMOS settings, as well as read and write to the buckets service, which holds configuration, log, and plugin files. These actions are normally only available from the Admin Console or with administrative privileges. Any user with permission to create and run scripts can connect to any service in the docker network. Figure 1: Environment variables, including Redis credentials, found in the Script Runner container A Ruby script is used to expose the Redis username, password, hostname, and port. These credentials might also be found from the source code or through a brute-force attack. Figure 2: A Python script is used to add data to Redis and retrieve the new data
A Python script is then used to create a new entry in the Redis database called Figure 3: The new data found in the Redis database
The new entry was successfully added to the Redis database, as is confirmed by using Figure 4: Uploading file to change the plugin store URL setting Figure 5: The URL file was successfully changed Steps To Reproduce
Recommendations• Limit the permissions of the script runner API to prevent lower level users from performing administrative actions Affected versions
5.0.10
5.0.11
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.10.0
5.10.1
5.11.0
5.11.1
+ 63 more Show less
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.2.0
5.20.0
5.3.0
5.4.0
5.4.1
5.4.2
5.4.3.pre.beta0
5.5.0
5.5.0.pre.beta0
5.5.1
5.5.2
5.5.2.pre.beta0
5.6.0
5.6.1
5.7.0
5.7.2
5.8.0
5.8.1
5.9.0
5.9.1
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.10.5
6.10.6
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
Fixed in
7.0.0-rc3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-42086
GHSA-ffq5-qpvf-xq7x
PYSEC-2026-105
Apr 22, 2026
OpenC3 COSMOS is Vulnerable to Self-XSS Through the Command Sender
4.6
/ 10
Medium
Network
Low
Low
Required
Unchanged
Low
Low
None
SummaryThe Command Sender UI uses an unsafe DetailsThe unsafe PoC
Below example uses ImpactLocal JavaScript execution in the user's browser Affected versions
5.0.10
5.0.11
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.10.0
5.10.1
5.11.0
5.11.1
+ 66 more Show less
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.2.0
5.20.0
5.3.0
5.4.0
5.4.1
5.4.2
5.4.3.pre.beta0
5.5.0
5.5.0.pre.beta0
5.5.1
5.5.2
5.5.2.pre.beta0
5.6.0
5.6.1
5.7.0
5.7.2
5.8.0
5.8.1
5.9.0
5.9.1
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.10.5
6.10.6
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
7.0.0.pre.rc1
7.0.0.pre.rc2
7.0.0.pre.rc3
Fixed in
7.0.0
References
Updated May 29, 2026 · Source: OSV.dev
CVE-2026-42085
GHSA-4jvx-93h3-f45h
PYSEC-2026-2243
Apr 22, 2026
OpenC3 COSMOS allows arbitrary writes to plugins directory via path-traversed config filenames
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
None
SummaryOpenC3 COSMOS contains a design flaw in the DetailsIn function PoC
ImpactModifying the data of other plugins Affected versions
5.0.10
5.0.11
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.10.0
5.10.1
5.11.0
5.11.1
+ 71 more Show less
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.2.0
5.20.0
5.3.0
5.4.0
5.4.1
5.4.2
5.4.3.pre.beta0
5.5.0
5.5.0.pre.beta0
5.5.1
5.5.2
5.5.2.pre.beta0
5.6.0
5.6.1
5.7.0
5.7.2
5.8.0
5.8.1
5.9.0
5.9.1
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
7.0.0
7.0.0.pre.rc1
7.0.0.pre.rc2
7.0.0.pre.rc3
7.0.1
7.1.0
7.1.1
7.2.0
7.2.1
7.3.0
Fixed in
6.10.5
7.0.0-rc3
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-42084
GHSA-wgx6-g857-jjf7
PYSEC-2026-2242
Apr 22, 2026
OpenC3 COSMOS: Hijacked session token can be used to reset password for persistence
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
SummaryThe OpenC3 password change functionality allows a user to change their password without providing the old password, by accepting a valid session token instead. In assumed breach scenarios, this behaviour can be exploited by an attacker who has already obtained a valid session token, to gain persistence in hijacked account (including admin) and prevent legitimate users from accessing the account. DetailsThe design flaw in authentication model (authentication.rb) allows for interchangeable use of password and session tokens for user authentication As old tokens are not revoked upon password reset, an attacker who has obtained a valid session token can continue to authenticate and change the account’s password even after the victim resets it, thereby maintaining persistent control over the compromised account. PoC
ImpactPersistence of an attacker who obtained valid session token and preventing legitimate users from account access Affected versions
5.0.10
5.0.11
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.10.0
5.10.1
5.11.0
5.11.1
+ 71 more Show less
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.2.0
5.20.0
5.3.0
5.4.0
5.4.1
5.4.2
5.4.3.pre.beta0
5.5.0
5.5.0.pre.beta0
5.5.1
5.5.2
5.5.2.pre.beta0
5.6.0
5.6.1
5.7.0
5.7.2
5.8.0
5.8.1
5.9.0
5.9.1
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
7.0.0
7.0.0.pre.rc1
7.0.0.pre.rc2
7.0.0.pre.rc3
7.0.1
7.1.0
7.1.1
7.2.0
7.2.1
7.3.0
Fixed in
6.10.5
7.0.0-rc3
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2025-68271
GHSA-w757-4qv9-mghp
Jan 13, 2026
openc3-api Vulnerable to Unauthenticated Remote Code Execution
10.0
/ 10
Critical
Network
Low
None
None
Changed
High
High
High
SummaryOpenC3 COSMOS contains a critical remote code execution vulnerability reachable through the JSON-RPC API. When a JSON-RPC request uses the string form of certain APIs, attacker-controlled parameter text is parsed into values using String#convert_to_value. For array-like inputs, convert_to_value executes eval(). Because the cmd code path parses the command string before calling authorize(), an unauthenticated attacker can trigger Ruby code execution even though the request ultimately fails authorization (401). Affected versions
5.0.10
5.0.11
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.10.0
5.10.1
5.11.0
5.11.1
+ 58 more Show less
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.2.0
5.20.0
5.3.0
5.4.0
5.4.1
5.4.2
5.4.3.pre.beta0
5.5.0
5.5.0.pre.beta0
5.5.1
5.5.2
5.5.2.pre.beta0
5.6.0
5.6.1
5.7.0
5.7.2
5.8.0
5.8.1
5.9.0
5.9.1
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
Fixed in
6.10.2
References
Updated Feb 03, 2026 · Source: OSV.dev
CVE-2024-47529
GHSA-4xqv-47rm-37mm
PYSEC-2024-121
Oct 02, 2024
OpenC3 stores passwords in clear text (`GHSL-2024-129`)
Medium
Network
Low
None
SummaryOpenC3 COSMOS stores the password of a user unencrypted in the LocalStorage of a web browser. This makes the user password susceptible to exfiltration via Cross-site scripting (see GHSL-2024-128). Note: This CVE only affects Open Source edition, and not OpenC3 COSMOS Enterprise Edition ImpactThis issue may lead to Information Disclosure. Affected versions
5.0.10
5.0.11
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.10.0
5.10.1
5.11.0
5.11.1
+ 35 more Show less
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.2.0
5.3.0
5.4.0
5.4.1
5.4.2
5.4.3.pre.beta0
5.5.0
5.5.0.pre.beta0
5.5.1
5.5.2
5.5.2.pre.beta0
5.6.0
5.6.1
5.7.0
5.7.2
5.8.0
5.8.1
5.9.0
5.9.1
Fixed in
5.19.0
References
Updated Nov 13, 2024 · Source: OSV.dev
CVE-2024-46977
GHSA-8jxr-mccc-mwg8
PYSEC-2024-101
Oct 02, 2024
OpenC3 Path Traversal via screen controller (`GHSL-2024-127`)
High
Network
Low
Low
None
SummaryA path traversal vulnerability inside of Note: This CVE affects all OpenC3 COSMOS Editions ImpactThis issue may lead to Information Disclosure. Affected versions
5.0.10
5.0.11
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.10.0
5.10.1
5.11.0
5.11.1
+ 35 more Show less
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.2.0
5.3.0
5.4.0
5.4.1
5.4.2
5.4.3.pre.beta0
5.5.0
5.5.0.pre.beta0
5.5.1
5.5.2
5.5.2.pre.beta0
5.6.0
5.6.1
5.7.0
5.7.2
5.8.0
5.8.1
5.9.0
5.9.1
Fixed in
5.19.0
References
Updated Oct 31, 2024 · Source: OSV.dev
CVE-2024-43795
GHSA-vfj8-5pj7-2f9g
PYSEC-2024-100
Oct 02, 2024
OpenC3 Cross-site Scripting in Login functionality (`GHSL-2024-128`)
Medium
Network
Low
None
SummaryThe login functionality contains a reflected cross-site scripting (XSS) vulnerability. Note: This CVE only affects Open Source Edition, and not OpenC3 COSMOS Enterprise Edition ImpactThis issue may lead up to Remote Code Execution (RCE). Affected versions
5.0.10
5.0.11
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.10.0
5.10.1
5.11.0
5.11.1
+ 35 more Show less
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.2.0
5.3.0
5.4.0
5.4.1
5.4.2
5.4.3.pre.beta0
5.5.0
5.5.0.pre.beta0
5.5.1
5.5.2
5.5.2.pre.beta0
5.6.0
5.6.1
5.7.0
5.7.2
5.8.0
5.8.1
5.9.0
5.9.1
Fixed in
5.19.0
References
Updated Oct 31, 2024 · Source: OSV.dev |
5.18.0
minor
Dependencies (53)
+ 45 more
Changelog
Compare changes
|
|
5.17.1
patch
8 CVEs
CVE-2026-42088
GHSA-2wvh-87g2-89hr
PYSEC-2026-2245
Apr 23, 2026
OpenC3 COSMOS: Permissions Bypass Provides User Access to Unassigned Administrative Actions via Script Runner Tool
9.6
/ 10
Critical
Network
Low
Low
None
Changed
High
High
None
Vulnerability Type: Execution with Unnecessary Privileges Attack type: Authenticated remote Impact: Data disclosure/manipulation, privilege escalation Affected components: The following docker images: • Openc3inc/openc3-COSMOS-script-runner-api The Script Runner widget allows users to execute Python and Ruby scripts directly from the openc3-COSMOS-script-runner-api container. Because all the docker containers share a network, users can execute specially crafted scripts to bypass the API permissions check and perform administrative actions, including reading and modifying data inside the Redis database, which can be used to read secrets and change COSMOS settings, as well as read and write to the buckets service, which holds configuration, log, and plugin files. These actions are normally only available from the Admin Console or with administrative privileges. Any user with permission to create and run scripts can connect to any service in the docker network. Figure 1: Environment variables, including Redis credentials, found in the Script Runner container A Ruby script is used to expose the Redis username, password, hostname, and port. These credentials might also be found from the source code or through a brute-force attack. Figure 2: A Python script is used to add data to Redis and retrieve the new data
A Python script is then used to create a new entry in the Redis database called Figure 3: The new data found in the Redis database
The new entry was successfully added to the Redis database, as is confirmed by using Figure 4: Uploading file to change the plugin store URL setting Figure 5: The URL file was successfully changed Steps To Reproduce
Recommendations• Limit the permissions of the script runner API to prevent lower level users from performing administrative actions Affected versions
5.0.10
5.0.11
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.10.0
5.10.1
5.11.0
5.11.1
+ 63 more Show less
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.2.0
5.20.0
5.3.0
5.4.0
5.4.1
5.4.2
5.4.3.pre.beta0
5.5.0
5.5.0.pre.beta0
5.5.1
5.5.2
5.5.2.pre.beta0
5.6.0
5.6.1
5.7.0
5.7.2
5.8.0
5.8.1
5.9.0
5.9.1
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.10.5
6.10.6
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
Fixed in
7.0.0-rc3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-42086
GHSA-ffq5-qpvf-xq7x
PYSEC-2026-105
Apr 22, 2026
OpenC3 COSMOS is Vulnerable to Self-XSS Through the Command Sender
4.6
/ 10
Medium
Network
Low
Low
Required
Unchanged
Low
Low
None
SummaryThe Command Sender UI uses an unsafe DetailsThe unsafe PoC
Below example uses ImpactLocal JavaScript execution in the user's browser Affected versions
5.0.10
5.0.11
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.10.0
5.10.1
5.11.0
5.11.1
+ 66 more Show less
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.2.0
5.20.0
5.3.0
5.4.0
5.4.1
5.4.2
5.4.3.pre.beta0
5.5.0
5.5.0.pre.beta0
5.5.1
5.5.2
5.5.2.pre.beta0
5.6.0
5.6.1
5.7.0
5.7.2
5.8.0
5.8.1
5.9.0
5.9.1
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.10.5
6.10.6
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
7.0.0.pre.rc1
7.0.0.pre.rc2
7.0.0.pre.rc3
Fixed in
7.0.0
References
Updated May 29, 2026 · Source: OSV.dev
CVE-2026-42085
GHSA-4jvx-93h3-f45h
PYSEC-2026-2243
Apr 22, 2026
OpenC3 COSMOS allows arbitrary writes to plugins directory via path-traversed config filenames
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
None
SummaryOpenC3 COSMOS contains a design flaw in the DetailsIn function PoC
ImpactModifying the data of other plugins Affected versions
5.0.10
5.0.11
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.10.0
5.10.1
5.11.0
5.11.1
+ 71 more Show less
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.2.0
5.20.0
5.3.0
5.4.0
5.4.1
5.4.2
5.4.3.pre.beta0
5.5.0
5.5.0.pre.beta0
5.5.1
5.5.2
5.5.2.pre.beta0
5.6.0
5.6.1
5.7.0
5.7.2
5.8.0
5.8.1
5.9.0
5.9.1
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
7.0.0
7.0.0.pre.rc1
7.0.0.pre.rc2
7.0.0.pre.rc3
7.0.1
7.1.0
7.1.1
7.2.0
7.2.1
7.3.0
Fixed in
6.10.5
7.0.0-rc3
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-42084
GHSA-wgx6-g857-jjf7
PYSEC-2026-2242
Apr 22, 2026
OpenC3 COSMOS: Hijacked session token can be used to reset password for persistence
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
SummaryThe OpenC3 password change functionality allows a user to change their password without providing the old password, by accepting a valid session token instead. In assumed breach scenarios, this behaviour can be exploited by an attacker who has already obtained a valid session token, to gain persistence in hijacked account (including admin) and prevent legitimate users from accessing the account. DetailsThe design flaw in authentication model (authentication.rb) allows for interchangeable use of password and session tokens for user authentication As old tokens are not revoked upon password reset, an attacker who has obtained a valid session token can continue to authenticate and change the account’s password even after the victim resets it, thereby maintaining persistent control over the compromised account. PoC
ImpactPersistence of an attacker who obtained valid session token and preventing legitimate users from account access Affected versions
5.0.10
5.0.11
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.10.0
5.10.1
5.11.0
5.11.1
+ 71 more Show less
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.2.0
5.20.0
5.3.0
5.4.0
5.4.1
5.4.2
5.4.3.pre.beta0
5.5.0
5.5.0.pre.beta0
5.5.1
5.5.2
5.5.2.pre.beta0
5.6.0
5.6.1
5.7.0
5.7.2
5.8.0
5.8.1
5.9.0
5.9.1
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
7.0.0
7.0.0.pre.rc1
7.0.0.pre.rc2
7.0.0.pre.rc3
7.0.1
7.1.0
7.1.1
7.2.0
7.2.1
7.3.0
Fixed in
6.10.5
7.0.0-rc3
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2025-68271
GHSA-w757-4qv9-mghp
Jan 13, 2026
openc3-api Vulnerable to Unauthenticated Remote Code Execution
10.0
/ 10
Critical
Network
Low
None
None
Changed
High
High
High
SummaryOpenC3 COSMOS contains a critical remote code execution vulnerability reachable through the JSON-RPC API. When a JSON-RPC request uses the string form of certain APIs, attacker-controlled parameter text is parsed into values using String#convert_to_value. For array-like inputs, convert_to_value executes eval(). Because the cmd code path parses the command string before calling authorize(), an unauthenticated attacker can trigger Ruby code execution even though the request ultimately fails authorization (401). Affected versions
5.0.10
5.0.11
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.10.0
5.10.1
5.11.0
5.11.1
+ 58 more Show less
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.2.0
5.20.0
5.3.0
5.4.0
5.4.1
5.4.2
5.4.3.pre.beta0
5.5.0
5.5.0.pre.beta0
5.5.1
5.5.2
5.5.2.pre.beta0
5.6.0
5.6.1
5.7.0
5.7.2
5.8.0
5.8.1
5.9.0
5.9.1
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
Fixed in
6.10.2
References
Updated Feb 03, 2026 · Source: OSV.dev
CVE-2024-47529
GHSA-4xqv-47rm-37mm
PYSEC-2024-121
Oct 02, 2024
OpenC3 stores passwords in clear text (`GHSL-2024-129`)
Medium
Network
Low
None
SummaryOpenC3 COSMOS stores the password of a user unencrypted in the LocalStorage of a web browser. This makes the user password susceptible to exfiltration via Cross-site scripting (see GHSL-2024-128). Note: This CVE only affects Open Source edition, and not OpenC3 COSMOS Enterprise Edition ImpactThis issue may lead to Information Disclosure. Affected versions
5.0.10
5.0.11
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.10.0
5.10.1
5.11.0
5.11.1
+ 35 more Show less
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.2.0
5.3.0
5.4.0
5.4.1
5.4.2
5.4.3.pre.beta0
5.5.0
5.5.0.pre.beta0
5.5.1
5.5.2
5.5.2.pre.beta0
5.6.0
5.6.1
5.7.0
5.7.2
5.8.0
5.8.1
5.9.0
5.9.1
Fixed in
5.19.0
References
Updated Nov 13, 2024 · Source: OSV.dev
CVE-2024-46977
GHSA-8jxr-mccc-mwg8
PYSEC-2024-101
Oct 02, 2024
OpenC3 Path Traversal via screen controller (`GHSL-2024-127`)
High
Network
Low
Low
None
SummaryA path traversal vulnerability inside of Note: This CVE affects all OpenC3 COSMOS Editions ImpactThis issue may lead to Information Disclosure. Affected versions
5.0.10
5.0.11
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.10.0
5.10.1
5.11.0
5.11.1
+ 35 more Show less
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.2.0
5.3.0
5.4.0
5.4.1
5.4.2
5.4.3.pre.beta0
5.5.0
5.5.0.pre.beta0
5.5.1
5.5.2
5.5.2.pre.beta0
5.6.0
5.6.1
5.7.0
5.7.2
5.8.0
5.8.1
5.9.0
5.9.1
Fixed in
5.19.0
References
Updated Oct 31, 2024 · Source: OSV.dev
CVE-2024-43795
GHSA-vfj8-5pj7-2f9g
PYSEC-2024-100
Oct 02, 2024
OpenC3 Cross-site Scripting in Login functionality (`GHSL-2024-128`)
Medium
Network
Low
None
SummaryThe login functionality contains a reflected cross-site scripting (XSS) vulnerability. Note: This CVE only affects Open Source Edition, and not OpenC3 COSMOS Enterprise Edition ImpactThis issue may lead up to Remote Code Execution (RCE). Affected versions
5.0.10
5.0.11
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.10.0
5.10.1
5.11.0
5.11.1
+ 35 more Show less
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.2.0
5.3.0
5.4.0
5.4.1
5.4.2
5.4.3.pre.beta0
5.5.0
5.5.0.pre.beta0
5.5.1
5.5.2
5.5.2.pre.beta0
5.6.0
5.6.1
5.7.0
5.7.2
5.8.0
5.8.1
5.9.0
5.9.1
Fixed in
5.19.0
References
Updated Oct 31, 2024 · Source: OSV.dev |
5.17.1
patch
Dependencies (52)
+ 44 more
Changelog
Compare changes
|
|
5.17.0
minor
8 CVEs
CVE-2026-42088
GHSA-2wvh-87g2-89hr
PYSEC-2026-2245
Apr 23, 2026
OpenC3 COSMOS: Permissions Bypass Provides User Access to Unassigned Administrative Actions via Script Runner Tool
9.6
/ 10
Critical
Network
Low
Low
None
Changed
High
High
None
Vulnerability Type: Execution with Unnecessary Privileges Attack type: Authenticated remote Impact: Data disclosure/manipulation, privilege escalation Affected components: The following docker images: • Openc3inc/openc3-COSMOS-script-runner-api The Script Runner widget allows users to execute Python and Ruby scripts directly from the openc3-COSMOS-script-runner-api container. Because all the docker containers share a network, users can execute specially crafted scripts to bypass the API permissions check and perform administrative actions, including reading and modifying data inside the Redis database, which can be used to read secrets and change COSMOS settings, as well as read and write to the buckets service, which holds configuration, log, and plugin files. These actions are normally only available from the Admin Console or with administrative privileges. Any user with permission to create and run scripts can connect to any service in the docker network. Figure 1: Environment variables, including Redis credentials, found in the Script Runner container A Ruby script is used to expose the Redis username, password, hostname, and port. These credentials might also be found from the source code or through a brute-force attack. Figure 2: A Python script is used to add data to Redis and retrieve the new data
A Python script is then used to create a new entry in the Redis database called Figure 3: The new data found in the Redis database
The new entry was successfully added to the Redis database, as is confirmed by using Figure 4: Uploading file to change the plugin store URL setting Figure 5: The URL file was successfully changed Steps To Reproduce
Recommendations• Limit the permissions of the script runner API to prevent lower level users from performing administrative actions Affected versions
5.0.10
5.0.11
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.10.0
5.10.1
5.11.0
5.11.1
+ 63 more Show less
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.2.0
5.20.0
5.3.0
5.4.0
5.4.1
5.4.2
5.4.3.pre.beta0
5.5.0
5.5.0.pre.beta0
5.5.1
5.5.2
5.5.2.pre.beta0
5.6.0
5.6.1
5.7.0
5.7.2
5.8.0
5.8.1
5.9.0
5.9.1
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.10.5
6.10.6
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
Fixed in
7.0.0-rc3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-42086
GHSA-ffq5-qpvf-xq7x
PYSEC-2026-105
Apr 22, 2026
OpenC3 COSMOS is Vulnerable to Self-XSS Through the Command Sender
4.6
/ 10
Medium
Network
Low
Low
Required
Unchanged
Low
Low
None
SummaryThe Command Sender UI uses an unsafe DetailsThe unsafe PoC
Below example uses ImpactLocal JavaScript execution in the user's browser Affected versions
5.0.10
5.0.11
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.10.0
5.10.1
5.11.0
5.11.1
+ 66 more Show less
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.2.0
5.20.0
5.3.0
5.4.0
5.4.1
5.4.2
5.4.3.pre.beta0
5.5.0
5.5.0.pre.beta0
5.5.1
5.5.2
5.5.2.pre.beta0
5.6.0
5.6.1
5.7.0
5.7.2
5.8.0
5.8.1
5.9.0
5.9.1
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.10.5
6.10.6
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
7.0.0.pre.rc1
7.0.0.pre.rc2
7.0.0.pre.rc3
Fixed in
7.0.0
References
Updated May 29, 2026 · Source: OSV.dev
CVE-2026-42085
GHSA-4jvx-93h3-f45h
PYSEC-2026-2243
Apr 22, 2026
OpenC3 COSMOS allows arbitrary writes to plugins directory via path-traversed config filenames
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
None
SummaryOpenC3 COSMOS contains a design flaw in the DetailsIn function PoC
ImpactModifying the data of other plugins Affected versions
5.0.10
5.0.11
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.10.0
5.10.1
5.11.0
5.11.1
+ 71 more Show less
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.2.0
5.20.0
5.3.0
5.4.0
5.4.1
5.4.2
5.4.3.pre.beta0
5.5.0
5.5.0.pre.beta0
5.5.1
5.5.2
5.5.2.pre.beta0
5.6.0
5.6.1
5.7.0
5.7.2
5.8.0
5.8.1
5.9.0
5.9.1
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
7.0.0
7.0.0.pre.rc1
7.0.0.pre.rc2
7.0.0.pre.rc3
7.0.1
7.1.0
7.1.1
7.2.0
7.2.1
7.3.0
Fixed in
6.10.5
7.0.0-rc3
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-42084
GHSA-wgx6-g857-jjf7
PYSEC-2026-2242
Apr 22, 2026
OpenC3 COSMOS: Hijacked session token can be used to reset password for persistence
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
SummaryThe OpenC3 password change functionality allows a user to change their password without providing the old password, by accepting a valid session token instead. In assumed breach scenarios, this behaviour can be exploited by an attacker who has already obtained a valid session token, to gain persistence in hijacked account (including admin) and prevent legitimate users from accessing the account. DetailsThe design flaw in authentication model (authentication.rb) allows for interchangeable use of password and session tokens for user authentication As old tokens are not revoked upon password reset, an attacker who has obtained a valid session token can continue to authenticate and change the account’s password even after the victim resets it, thereby maintaining persistent control over the compromised account. PoC
ImpactPersistence of an attacker who obtained valid session token and preventing legitimate users from account access Affected versions
5.0.10
5.0.11
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.10.0
5.10.1
5.11.0
5.11.1
+ 71 more Show less
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.2.0
5.20.0
5.3.0
5.4.0
5.4.1
5.4.2
5.4.3.pre.beta0
5.5.0
5.5.0.pre.beta0
5.5.1
5.5.2
5.5.2.pre.beta0
5.6.0
5.6.1
5.7.0
5.7.2
5.8.0
5.8.1
5.9.0
5.9.1
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
7.0.0
7.0.0.pre.rc1
7.0.0.pre.rc2
7.0.0.pre.rc3
7.0.1
7.1.0
7.1.1
7.2.0
7.2.1
7.3.0
Fixed in
6.10.5
7.0.0-rc3
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2025-68271
GHSA-w757-4qv9-mghp
Jan 13, 2026
openc3-api Vulnerable to Unauthenticated Remote Code Execution
10.0
/ 10
Critical
Network
Low
None
None
Changed
High
High
High
SummaryOpenC3 COSMOS contains a critical remote code execution vulnerability reachable through the JSON-RPC API. When a JSON-RPC request uses the string form of certain APIs, attacker-controlled parameter text is parsed into values using String#convert_to_value. For array-like inputs, convert_to_value executes eval(). Because the cmd code path parses the command string before calling authorize(), an unauthenticated attacker can trigger Ruby code execution even though the request ultimately fails authorization (401). Affected versions
5.0.10
5.0.11
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.10.0
5.10.1
5.11.0
5.11.1
+ 58 more Show less
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.2.0
5.20.0
5.3.0
5.4.0
5.4.1
5.4.2
5.4.3.pre.beta0
5.5.0
5.5.0.pre.beta0
5.5.1
5.5.2
5.5.2.pre.beta0
5.6.0
5.6.1
5.7.0
5.7.2
5.8.0
5.8.1
5.9.0
5.9.1
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
Fixed in
6.10.2
References
Updated Feb 03, 2026 · Source: OSV.dev
CVE-2024-47529
GHSA-4xqv-47rm-37mm
PYSEC-2024-121
Oct 02, 2024
OpenC3 stores passwords in clear text (`GHSL-2024-129`)
Medium
Network
Low
None
SummaryOpenC3 COSMOS stores the password of a user unencrypted in the LocalStorage of a web browser. This makes the user password susceptible to exfiltration via Cross-site scripting (see GHSL-2024-128). Note: This CVE only affects Open Source edition, and not OpenC3 COSMOS Enterprise Edition ImpactThis issue may lead to Information Disclosure. Affected versions
5.0.10
5.0.11
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.10.0
5.10.1
5.11.0
5.11.1
+ 35 more Show less
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.2.0
5.3.0
5.4.0
5.4.1
5.4.2
5.4.3.pre.beta0
5.5.0
5.5.0.pre.beta0
5.5.1
5.5.2
5.5.2.pre.beta0
5.6.0
5.6.1
5.7.0
5.7.2
5.8.0
5.8.1
5.9.0
5.9.1
Fixed in
5.19.0
References
Updated Nov 13, 2024 · Source: OSV.dev
CVE-2024-46977
GHSA-8jxr-mccc-mwg8
PYSEC-2024-101
Oct 02, 2024
OpenC3 Path Traversal via screen controller (`GHSL-2024-127`)
High
Network
Low
Low
None
SummaryA path traversal vulnerability inside of Note: This CVE affects all OpenC3 COSMOS Editions ImpactThis issue may lead to Information Disclosure. Affected versions
5.0.10
5.0.11
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.10.0
5.10.1
5.11.0
5.11.1
+ 35 more Show less
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.2.0
5.3.0
5.4.0
5.4.1
5.4.2
5.4.3.pre.beta0
5.5.0
5.5.0.pre.beta0
5.5.1
5.5.2
5.5.2.pre.beta0
5.6.0
5.6.1
5.7.0
5.7.2
5.8.0
5.8.1
5.9.0
5.9.1
Fixed in
5.19.0
References
Updated Oct 31, 2024 · Source: OSV.dev
CVE-2024-43795
GHSA-vfj8-5pj7-2f9g
PYSEC-2024-100
Oct 02, 2024
OpenC3 Cross-site Scripting in Login functionality (`GHSL-2024-128`)
Medium
Network
Low
None
SummaryThe login functionality contains a reflected cross-site scripting (XSS) vulnerability. Note: This CVE only affects Open Source Edition, and not OpenC3 COSMOS Enterprise Edition ImpactThis issue may lead up to Remote Code Execution (RCE). Affected versions
5.0.10
5.0.11
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.10.0
5.10.1
5.11.0
5.11.1
+ 35 more Show less
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.2.0
5.3.0
5.4.0
5.4.1
5.4.2
5.4.3.pre.beta0
5.5.0
5.5.0.pre.beta0
5.5.1
5.5.2
5.5.2.pre.beta0
5.6.0
5.6.1
5.7.0
5.7.2
5.8.0
5.8.1
5.9.0
5.9.1
Fixed in
5.19.0
References
Updated Oct 31, 2024 · Source: OSV.dev |
5.17.0
minor
Dependencies (52)
+ 44 more
Changelog
Compare changes
|
|
5.16.2
patch
8 CVEs
CVE-2026-42088
GHSA-2wvh-87g2-89hr
PYSEC-2026-2245
Apr 23, 2026
OpenC3 COSMOS: Permissions Bypass Provides User Access to Unassigned Administrative Actions via Script Runner Tool
9.6
/ 10
Critical
Network
Low
Low
None
Changed
High
High
None
Vulnerability Type: Execution with Unnecessary Privileges Attack type: Authenticated remote Impact: Data disclosure/manipulation, privilege escalation Affected components: The following docker images: • Openc3inc/openc3-COSMOS-script-runner-api The Script Runner widget allows users to execute Python and Ruby scripts directly from the openc3-COSMOS-script-runner-api container. Because all the docker containers share a network, users can execute specially crafted scripts to bypass the API permissions check and perform administrative actions, including reading and modifying data inside the Redis database, which can be used to read secrets and change COSMOS settings, as well as read and write to the buckets service, which holds configuration, log, and plugin files. These actions are normally only available from the Admin Console or with administrative privileges. Any user with permission to create and run scripts can connect to any service in the docker network. Figure 1: Environment variables, including Redis credentials, found in the Script Runner container A Ruby script is used to expose the Redis username, password, hostname, and port. These credentials might also be found from the source code or through a brute-force attack. Figure 2: A Python script is used to add data to Redis and retrieve the new data
A Python script is then used to create a new entry in the Redis database called Figure 3: The new data found in the Redis database
The new entry was successfully added to the Redis database, as is confirmed by using Figure 4: Uploading file to change the plugin store URL setting Figure 5: The URL file was successfully changed Steps To Reproduce
Recommendations• Limit the permissions of the script runner API to prevent lower level users from performing administrative actions Affected versions
5.0.10
5.0.11
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.10.0
5.10.1
5.11.0
5.11.1
+ 63 more Show less
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.2.0
5.20.0
5.3.0
5.4.0
5.4.1
5.4.2
5.4.3.pre.beta0
5.5.0
5.5.0.pre.beta0
5.5.1
5.5.2
5.5.2.pre.beta0
5.6.0
5.6.1
5.7.0
5.7.2
5.8.0
5.8.1
5.9.0
5.9.1
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.10.5
6.10.6
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
Fixed in
7.0.0-rc3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-42086
GHSA-ffq5-qpvf-xq7x
PYSEC-2026-105
Apr 22, 2026
OpenC3 COSMOS is Vulnerable to Self-XSS Through the Command Sender
4.6
/ 10
Medium
Network
Low
Low
Required
Unchanged
Low
Low
None
SummaryThe Command Sender UI uses an unsafe DetailsThe unsafe PoC
Below example uses ImpactLocal JavaScript execution in the user's browser Affected versions
5.0.10
5.0.11
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.10.0
5.10.1
5.11.0
5.11.1
+ 66 more Show less
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.2.0
5.20.0
5.3.0
5.4.0
5.4.1
5.4.2
5.4.3.pre.beta0
5.5.0
5.5.0.pre.beta0
5.5.1
5.5.2
5.5.2.pre.beta0
5.6.0
5.6.1
5.7.0
5.7.2
5.8.0
5.8.1
5.9.0
5.9.1
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.10.5
6.10.6
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
7.0.0.pre.rc1
7.0.0.pre.rc2
7.0.0.pre.rc3
Fixed in
7.0.0
References
Updated May 29, 2026 · Source: OSV.dev
CVE-2026-42085
GHSA-4jvx-93h3-f45h
PYSEC-2026-2243
Apr 22, 2026
OpenC3 COSMOS allows arbitrary writes to plugins directory via path-traversed config filenames
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
None
SummaryOpenC3 COSMOS contains a design flaw in the DetailsIn function PoC
ImpactModifying the data of other plugins Affected versions
5.0.10
5.0.11
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.10.0
5.10.1
5.11.0
5.11.1
+ 71 more Show less
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.2.0
5.20.0
5.3.0
5.4.0
5.4.1
5.4.2
5.4.3.pre.beta0
5.5.0
5.5.0.pre.beta0
5.5.1
5.5.2
5.5.2.pre.beta0
5.6.0
5.6.1
5.7.0
5.7.2
5.8.0
5.8.1
5.9.0
5.9.1
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
7.0.0
7.0.0.pre.rc1
7.0.0.pre.rc2
7.0.0.pre.rc3
7.0.1
7.1.0
7.1.1
7.2.0
7.2.1
7.3.0
Fixed in
6.10.5
7.0.0-rc3
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-42084
GHSA-wgx6-g857-jjf7
PYSEC-2026-2242
Apr 22, 2026
OpenC3 COSMOS: Hijacked session token can be used to reset password for persistence
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
SummaryThe OpenC3 password change functionality allows a user to change their password without providing the old password, by accepting a valid session token instead. In assumed breach scenarios, this behaviour can be exploited by an attacker who has already obtained a valid session token, to gain persistence in hijacked account (including admin) and prevent legitimate users from accessing the account. DetailsThe design flaw in authentication model (authentication.rb) allows for interchangeable use of password and session tokens for user authentication As old tokens are not revoked upon password reset, an attacker who has obtained a valid session token can continue to authenticate and change the account’s password even after the victim resets it, thereby maintaining persistent control over the compromised account. PoC
ImpactPersistence of an attacker who obtained valid session token and preventing legitimate users from account access Affected versions
5.0.10
5.0.11
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.10.0
5.10.1
5.11.0
5.11.1
+ 71 more Show less
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.2.0
5.20.0
5.3.0
5.4.0
5.4.1
5.4.2
5.4.3.pre.beta0
5.5.0
5.5.0.pre.beta0
5.5.1
5.5.2
5.5.2.pre.beta0
5.6.0
5.6.1
5.7.0
5.7.2
5.8.0
5.8.1
5.9.0
5.9.1
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
7.0.0
7.0.0.pre.rc1
7.0.0.pre.rc2
7.0.0.pre.rc3
7.0.1
7.1.0
7.1.1
7.2.0
7.2.1
7.3.0
Fixed in
6.10.5
7.0.0-rc3
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2025-68271
GHSA-w757-4qv9-mghp
Jan 13, 2026
openc3-api Vulnerable to Unauthenticated Remote Code Execution
10.0
/ 10
Critical
Network
Low
None
None
Changed
High
High
High
SummaryOpenC3 COSMOS contains a critical remote code execution vulnerability reachable through the JSON-RPC API. When a JSON-RPC request uses the string form of certain APIs, attacker-controlled parameter text is parsed into values using String#convert_to_value. For array-like inputs, convert_to_value executes eval(). Because the cmd code path parses the command string before calling authorize(), an unauthenticated attacker can trigger Ruby code execution even though the request ultimately fails authorization (401). Affected versions
5.0.10
5.0.11
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.10.0
5.10.1
5.11.0
5.11.1
+ 58 more Show less
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.2.0
5.20.0
5.3.0
5.4.0
5.4.1
5.4.2
5.4.3.pre.beta0
5.5.0
5.5.0.pre.beta0
5.5.1
5.5.2
5.5.2.pre.beta0
5.6.0
5.6.1
5.7.0
5.7.2
5.8.0
5.8.1
5.9.0
5.9.1
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
Fixed in
6.10.2
References
Updated Feb 03, 2026 · Source: OSV.dev
CVE-2024-47529
GHSA-4xqv-47rm-37mm
PYSEC-2024-121
Oct 02, 2024
OpenC3 stores passwords in clear text (`GHSL-2024-129`)
Medium
Network
Low
None
SummaryOpenC3 COSMOS stores the password of a user unencrypted in the LocalStorage of a web browser. This makes the user password susceptible to exfiltration via Cross-site scripting (see GHSL-2024-128). Note: This CVE only affects Open Source edition, and not OpenC3 COSMOS Enterprise Edition ImpactThis issue may lead to Information Disclosure. Affected versions
5.0.10
5.0.11
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.10.0
5.10.1
5.11.0
5.11.1
+ 35 more Show less
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.2.0
5.3.0
5.4.0
5.4.1
5.4.2
5.4.3.pre.beta0
5.5.0
5.5.0.pre.beta0
5.5.1
5.5.2
5.5.2.pre.beta0
5.6.0
5.6.1
5.7.0
5.7.2
5.8.0
5.8.1
5.9.0
5.9.1
Fixed in
5.19.0
References
Updated Nov 13, 2024 · Source: OSV.dev
CVE-2024-46977
GHSA-8jxr-mccc-mwg8
PYSEC-2024-101
Oct 02, 2024
OpenC3 Path Traversal via screen controller (`GHSL-2024-127`)
High
Network
Low
Low
None
SummaryA path traversal vulnerability inside of Note: This CVE affects all OpenC3 COSMOS Editions ImpactThis issue may lead to Information Disclosure. Affected versions
5.0.10
5.0.11
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.10.0
5.10.1
5.11.0
5.11.1
+ 35 more Show less
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.2.0
5.3.0
5.4.0
5.4.1
5.4.2
5.4.3.pre.beta0
5.5.0
5.5.0.pre.beta0
5.5.1
5.5.2
5.5.2.pre.beta0
5.6.0
5.6.1
5.7.0
5.7.2
5.8.0
5.8.1
5.9.0
5.9.1
Fixed in
5.19.0
References
Updated Oct 31, 2024 · Source: OSV.dev
CVE-2024-43795
GHSA-vfj8-5pj7-2f9g
PYSEC-2024-100
Oct 02, 2024
OpenC3 Cross-site Scripting in Login functionality (`GHSL-2024-128`)
Medium
Network
Low
None
SummaryThe login functionality contains a reflected cross-site scripting (XSS) vulnerability. Note: This CVE only affects Open Source Edition, and not OpenC3 COSMOS Enterprise Edition ImpactThis issue may lead up to Remote Code Execution (RCE). Affected versions
5.0.10
5.0.11
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.10.0
5.10.1
5.11.0
5.11.1
+ 35 more Show less
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.2.0
5.3.0
5.4.0
5.4.1
5.4.2
5.4.3.pre.beta0
5.5.0
5.5.0.pre.beta0
5.5.1
5.5.2
5.5.2.pre.beta0
5.6.0
5.6.1
5.7.0
5.7.2
5.8.0
5.8.1
5.9.0
5.9.1
Fixed in
5.19.0
References
Updated Oct 31, 2024 · Source: OSV.dev |
5.16.2
patch
Dependencies (52)
+ 44 more
Changelog
Compare changes
|
|
5.16.1
patch
8 CVEs
CVE-2026-42088
GHSA-2wvh-87g2-89hr
PYSEC-2026-2245
Apr 23, 2026
OpenC3 COSMOS: Permissions Bypass Provides User Access to Unassigned Administrative Actions via Script Runner Tool
9.6
/ 10
Critical
Network
Low
Low
None
Changed
High
High
None
Vulnerability Type: Execution with Unnecessary Privileges Attack type: Authenticated remote Impact: Data disclosure/manipulation, privilege escalation Affected components: The following docker images: • Openc3inc/openc3-COSMOS-script-runner-api The Script Runner widget allows users to execute Python and Ruby scripts directly from the openc3-COSMOS-script-runner-api container. Because all the docker containers share a network, users can execute specially crafted scripts to bypass the API permissions check and perform administrative actions, including reading and modifying data inside the Redis database, which can be used to read secrets and change COSMOS settings, as well as read and write to the buckets service, which holds configuration, log, and plugin files. These actions are normally only available from the Admin Console or with administrative privileges. Any user with permission to create and run scripts can connect to any service in the docker network. Figure 1: Environment variables, including Redis credentials, found in the Script Runner container A Ruby script is used to expose the Redis username, password, hostname, and port. These credentials might also be found from the source code or through a brute-force attack. Figure 2: A Python script is used to add data to Redis and retrieve the new data
A Python script is then used to create a new entry in the Redis database called Figure 3: The new data found in the Redis database
The new entry was successfully added to the Redis database, as is confirmed by using Figure 4: Uploading file to change the plugin store URL setting Figure 5: The URL file was successfully changed Steps To Reproduce
Recommendations• Limit the permissions of the script runner API to prevent lower level users from performing administrative actions Affected versions
5.0.10
5.0.11
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.10.0
5.10.1
5.11.0
5.11.1
+ 63 more Show less
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.2.0
5.20.0
5.3.0
5.4.0
5.4.1
5.4.2
5.4.3.pre.beta0
5.5.0
5.5.0.pre.beta0
5.5.1
5.5.2
5.5.2.pre.beta0
5.6.0
5.6.1
5.7.0
5.7.2
5.8.0
5.8.1
5.9.0
5.9.1
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.10.5
6.10.6
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
Fixed in
7.0.0-rc3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-42086
GHSA-ffq5-qpvf-xq7x
PYSEC-2026-105
Apr 22, 2026
OpenC3 COSMOS is Vulnerable to Self-XSS Through the Command Sender
4.6
/ 10
Medium
Network
Low
Low
Required
Unchanged
Low
Low
None
SummaryThe Command Sender UI uses an unsafe DetailsThe unsafe PoC
Below example uses ImpactLocal JavaScript execution in the user's browser Affected versions
5.0.10
5.0.11
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.10.0
5.10.1
5.11.0
5.11.1
+ 66 more Show less
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.2.0
5.20.0
5.3.0
5.4.0
5.4.1
5.4.2
5.4.3.pre.beta0
5.5.0
5.5.0.pre.beta0
5.5.1
5.5.2
5.5.2.pre.beta0
5.6.0
5.6.1
5.7.0
5.7.2
5.8.0
5.8.1
5.9.0
5.9.1
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.10.5
6.10.6
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
7.0.0.pre.rc1
7.0.0.pre.rc2
7.0.0.pre.rc3
Fixed in
7.0.0
References
Updated May 29, 2026 · Source: OSV.dev
CVE-2026-42085
GHSA-4jvx-93h3-f45h
PYSEC-2026-2243
Apr 22, 2026
OpenC3 COSMOS allows arbitrary writes to plugins directory via path-traversed config filenames
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
None
SummaryOpenC3 COSMOS contains a design flaw in the DetailsIn function PoC
ImpactModifying the data of other plugins Affected versions
5.0.10
5.0.11
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.10.0
5.10.1
5.11.0
5.11.1
+ 71 more Show less
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.2.0
5.20.0
5.3.0
5.4.0
5.4.1
5.4.2
5.4.3.pre.beta0
5.5.0
5.5.0.pre.beta0
5.5.1
5.5.2
5.5.2.pre.beta0
5.6.0
5.6.1
5.7.0
5.7.2
5.8.0
5.8.1
5.9.0
5.9.1
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
7.0.0
7.0.0.pre.rc1
7.0.0.pre.rc2
7.0.0.pre.rc3
7.0.1
7.1.0
7.1.1
7.2.0
7.2.1
7.3.0
Fixed in
6.10.5
7.0.0-rc3
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-42084
GHSA-wgx6-g857-jjf7
PYSEC-2026-2242
Apr 22, 2026
OpenC3 COSMOS: Hijacked session token can be used to reset password for persistence
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
SummaryThe OpenC3 password change functionality allows a user to change their password without providing the old password, by accepting a valid session token instead. In assumed breach scenarios, this behaviour can be exploited by an attacker who has already obtained a valid session token, to gain persistence in hijacked account (including admin) and prevent legitimate users from accessing the account. DetailsThe design flaw in authentication model (authentication.rb) allows for interchangeable use of password and session tokens for user authentication As old tokens are not revoked upon password reset, an attacker who has obtained a valid session token can continue to authenticate and change the account’s password even after the victim resets it, thereby maintaining persistent control over the compromised account. PoC
ImpactPersistence of an attacker who obtained valid session token and preventing legitimate users from account access Affected versions
5.0.10
5.0.11
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.10.0
5.10.1
5.11.0
5.11.1
+ 71 more Show less
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.2.0
5.20.0
5.3.0
5.4.0
5.4.1
5.4.2
5.4.3.pre.beta0
5.5.0
5.5.0.pre.beta0
5.5.1
5.5.2
5.5.2.pre.beta0
5.6.0
5.6.1
5.7.0
5.7.2
5.8.0
5.8.1
5.9.0
5.9.1
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
7.0.0
7.0.0.pre.rc1
7.0.0.pre.rc2
7.0.0.pre.rc3
7.0.1
7.1.0
7.1.1
7.2.0
7.2.1
7.3.0
Fixed in
6.10.5
7.0.0-rc3
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2025-68271
GHSA-w757-4qv9-mghp
Jan 13, 2026
openc3-api Vulnerable to Unauthenticated Remote Code Execution
10.0
/ 10
Critical
Network
Low
None
None
Changed
High
High
High
SummaryOpenC3 COSMOS contains a critical remote code execution vulnerability reachable through the JSON-RPC API. When a JSON-RPC request uses the string form of certain APIs, attacker-controlled parameter text is parsed into values using String#convert_to_value. For array-like inputs, convert_to_value executes eval(). Because the cmd code path parses the command string before calling authorize(), an unauthenticated attacker can trigger Ruby code execution even though the request ultimately fails authorization (401). Affected versions
5.0.10
5.0.11
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.10.0
5.10.1
5.11.0
5.11.1
+ 58 more Show less
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.2.0
5.20.0
5.3.0
5.4.0
5.4.1
5.4.2
5.4.3.pre.beta0
5.5.0
5.5.0.pre.beta0
5.5.1
5.5.2
5.5.2.pre.beta0
5.6.0
5.6.1
5.7.0
5.7.2
5.8.0
5.8.1
5.9.0
5.9.1
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
Fixed in
6.10.2
References
Updated Feb 03, 2026 · Source: OSV.dev
CVE-2024-47529
GHSA-4xqv-47rm-37mm
PYSEC-2024-121
Oct 02, 2024
OpenC3 stores passwords in clear text (`GHSL-2024-129`)
Medium
Network
Low
None
SummaryOpenC3 COSMOS stores the password of a user unencrypted in the LocalStorage of a web browser. This makes the user password susceptible to exfiltration via Cross-site scripting (see GHSL-2024-128). Note: This CVE only affects Open Source edition, and not OpenC3 COSMOS Enterprise Edition ImpactThis issue may lead to Information Disclosure. Affected versions
5.0.10
5.0.11
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.10.0
5.10.1
5.11.0
5.11.1
+ 35 more Show less
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.2.0
5.3.0
5.4.0
5.4.1
5.4.2
5.4.3.pre.beta0
5.5.0
5.5.0.pre.beta0
5.5.1
5.5.2
5.5.2.pre.beta0
5.6.0
5.6.1
5.7.0
5.7.2
5.8.0
5.8.1
5.9.0
5.9.1
Fixed in
5.19.0
References
Updated Nov 13, 2024 · Source: OSV.dev
CVE-2024-46977
GHSA-8jxr-mccc-mwg8
PYSEC-2024-101
Oct 02, 2024
OpenC3 Path Traversal via screen controller (`GHSL-2024-127`)
High
Network
Low
Low
None
SummaryA path traversal vulnerability inside of Note: This CVE affects all OpenC3 COSMOS Editions ImpactThis issue may lead to Information Disclosure. Affected versions
5.0.10
5.0.11
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.10.0
5.10.1
5.11.0
5.11.1
+ 35 more Show less
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.2.0
5.3.0
5.4.0
5.4.1
5.4.2
5.4.3.pre.beta0
5.5.0
5.5.0.pre.beta0
5.5.1
5.5.2
5.5.2.pre.beta0
5.6.0
5.6.1
5.7.0
5.7.2
5.8.0
5.8.1
5.9.0
5.9.1
Fixed in
5.19.0
References
Updated Oct 31, 2024 · Source: OSV.dev
CVE-2024-43795
GHSA-vfj8-5pj7-2f9g
PYSEC-2024-100
Oct 02, 2024
OpenC3 Cross-site Scripting in Login functionality (`GHSL-2024-128`)
Medium
Network
Low
None
SummaryThe login functionality contains a reflected cross-site scripting (XSS) vulnerability. Note: This CVE only affects Open Source Edition, and not OpenC3 COSMOS Enterprise Edition ImpactThis issue may lead up to Remote Code Execution (RCE). Affected versions
5.0.10
5.0.11
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.10.0
5.10.1
5.11.0
5.11.1
+ 35 more Show less
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.2.0
5.3.0
5.4.0
5.4.1
5.4.2
5.4.3.pre.beta0
5.5.0
5.5.0.pre.beta0
5.5.1
5.5.2
5.5.2.pre.beta0
5.6.0
5.6.1
5.7.0
5.7.2
5.8.0
5.8.1
5.9.0
5.9.1
Fixed in
5.19.0
References
Updated Oct 31, 2024 · Source: OSV.dev |
5.16.1
patch
Dependencies (52)
+ 44 more
Changelog
Compare changes
|
|
5.16.0
minor
8 CVEs
CVE-2026-42088
GHSA-2wvh-87g2-89hr
PYSEC-2026-2245
Apr 23, 2026
OpenC3 COSMOS: Permissions Bypass Provides User Access to Unassigned Administrative Actions via Script Runner Tool
9.6
/ 10
Critical
Network
Low
Low
None
Changed
High
High
None
Vulnerability Type: Execution with Unnecessary Privileges Attack type: Authenticated remote Impact: Data disclosure/manipulation, privilege escalation Affected components: The following docker images: • Openc3inc/openc3-COSMOS-script-runner-api The Script Runner widget allows users to execute Python and Ruby scripts directly from the openc3-COSMOS-script-runner-api container. Because all the docker containers share a network, users can execute specially crafted scripts to bypass the API permissions check and perform administrative actions, including reading and modifying data inside the Redis database, which can be used to read secrets and change COSMOS settings, as well as read and write to the buckets service, which holds configuration, log, and plugin files. These actions are normally only available from the Admin Console or with administrative privileges. Any user with permission to create and run scripts can connect to any service in the docker network. Figure 1: Environment variables, including Redis credentials, found in the Script Runner container A Ruby script is used to expose the Redis username, password, hostname, and port. These credentials might also be found from the source code or through a brute-force attack. Figure 2: A Python script is used to add data to Redis and retrieve the new data
A Python script is then used to create a new entry in the Redis database called Figure 3: The new data found in the Redis database
The new entry was successfully added to the Redis database, as is confirmed by using Figure 4: Uploading file to change the plugin store URL setting Figure 5: The URL file was successfully changed Steps To Reproduce
Recommendations• Limit the permissions of the script runner API to prevent lower level users from performing administrative actions Affected versions
5.0.10
5.0.11
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.10.0
5.10.1
5.11.0
5.11.1
+ 63 more Show less
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.2.0
5.20.0
5.3.0
5.4.0
5.4.1
5.4.2
5.4.3.pre.beta0
5.5.0
5.5.0.pre.beta0
5.5.1
5.5.2
5.5.2.pre.beta0
5.6.0
5.6.1
5.7.0
5.7.2
5.8.0
5.8.1
5.9.0
5.9.1
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.10.5
6.10.6
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
Fixed in
7.0.0-rc3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-42086
GHSA-ffq5-qpvf-xq7x
PYSEC-2026-105
Apr 22, 2026
OpenC3 COSMOS is Vulnerable to Self-XSS Through the Command Sender
4.6
/ 10
Medium
Network
Low
Low
Required
Unchanged
Low
Low
None
SummaryThe Command Sender UI uses an unsafe DetailsThe unsafe PoC
Below example uses ImpactLocal JavaScript execution in the user's browser Affected versions
5.0.10
5.0.11
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.10.0
5.10.1
5.11.0
5.11.1
+ 66 more Show less
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.2.0
5.20.0
5.3.0
5.4.0
5.4.1
5.4.2
5.4.3.pre.beta0
5.5.0
5.5.0.pre.beta0
5.5.1
5.5.2
5.5.2.pre.beta0
5.6.0
5.6.1
5.7.0
5.7.2
5.8.0
5.8.1
5.9.0
5.9.1
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.10.5
6.10.6
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
7.0.0.pre.rc1
7.0.0.pre.rc2
7.0.0.pre.rc3
Fixed in
7.0.0
References
Updated May 29, 2026 · Source: OSV.dev
CVE-2026-42085
GHSA-4jvx-93h3-f45h
PYSEC-2026-2243
Apr 22, 2026
OpenC3 COSMOS allows arbitrary writes to plugins directory via path-traversed config filenames
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
None
SummaryOpenC3 COSMOS contains a design flaw in the DetailsIn function PoC
ImpactModifying the data of other plugins Affected versions
5.0.10
5.0.11
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.10.0
5.10.1
5.11.0
5.11.1
+ 71 more Show less
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.2.0
5.20.0
5.3.0
5.4.0
5.4.1
5.4.2
5.4.3.pre.beta0
5.5.0
5.5.0.pre.beta0
5.5.1
5.5.2
5.5.2.pre.beta0
5.6.0
5.6.1
5.7.0
5.7.2
5.8.0
5.8.1
5.9.0
5.9.1
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
7.0.0
7.0.0.pre.rc1
7.0.0.pre.rc2
7.0.0.pre.rc3
7.0.1
7.1.0
7.1.1
7.2.0
7.2.1
7.3.0
Fixed in
6.10.5
7.0.0-rc3
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-42084
GHSA-wgx6-g857-jjf7
PYSEC-2026-2242
Apr 22, 2026
OpenC3 COSMOS: Hijacked session token can be used to reset password for persistence
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
SummaryThe OpenC3 password change functionality allows a user to change their password without providing the old password, by accepting a valid session token instead. In assumed breach scenarios, this behaviour can be exploited by an attacker who has already obtained a valid session token, to gain persistence in hijacked account (including admin) and prevent legitimate users from accessing the account. DetailsThe design flaw in authentication model (authentication.rb) allows for interchangeable use of password and session tokens for user authentication As old tokens are not revoked upon password reset, an attacker who has obtained a valid session token can continue to authenticate and change the account’s password even after the victim resets it, thereby maintaining persistent control over the compromised account. PoC
ImpactPersistence of an attacker who obtained valid session token and preventing legitimate users from account access Affected versions
5.0.10
5.0.11
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.10.0
5.10.1
5.11.0
5.11.1
+ 71 more Show less
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.2.0
5.20.0
5.3.0
5.4.0
5.4.1
5.4.2
5.4.3.pre.beta0
5.5.0
5.5.0.pre.beta0
5.5.1
5.5.2
5.5.2.pre.beta0
5.6.0
5.6.1
5.7.0
5.7.2
5.8.0
5.8.1
5.9.0
5.9.1
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
7.0.0
7.0.0.pre.rc1
7.0.0.pre.rc2
7.0.0.pre.rc3
7.0.1
7.1.0
7.1.1
7.2.0
7.2.1
7.3.0
Fixed in
6.10.5
7.0.0-rc3
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2025-68271
GHSA-w757-4qv9-mghp
Jan 13, 2026
openc3-api Vulnerable to Unauthenticated Remote Code Execution
10.0
/ 10
Critical
Network
Low
None
None
Changed
High
High
High
SummaryOpenC3 COSMOS contains a critical remote code execution vulnerability reachable through the JSON-RPC API. When a JSON-RPC request uses the string form of certain APIs, attacker-controlled parameter text is parsed into values using String#convert_to_value. For array-like inputs, convert_to_value executes eval(). Because the cmd code path parses the command string before calling authorize(), an unauthenticated attacker can trigger Ruby code execution even though the request ultimately fails authorization (401). Affected versions
5.0.10
5.0.11
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.10.0
5.10.1
5.11.0
5.11.1
+ 58 more Show less
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.2.0
5.20.0
5.3.0
5.4.0
5.4.1
5.4.2
5.4.3.pre.beta0
5.5.0
5.5.0.pre.beta0
5.5.1
5.5.2
5.5.2.pre.beta0
5.6.0
5.6.1
5.7.0
5.7.2
5.8.0
5.8.1
5.9.0
5.9.1
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
Fixed in
6.10.2
References
Updated Feb 03, 2026 · Source: OSV.dev
CVE-2024-47529
GHSA-4xqv-47rm-37mm
PYSEC-2024-121
Oct 02, 2024
OpenC3 stores passwords in clear text (`GHSL-2024-129`)
Medium
Network
Low
None
SummaryOpenC3 COSMOS stores the password of a user unencrypted in the LocalStorage of a web browser. This makes the user password susceptible to exfiltration via Cross-site scripting (see GHSL-2024-128). Note: This CVE only affects Open Source edition, and not OpenC3 COSMOS Enterprise Edition ImpactThis issue may lead to Information Disclosure. Affected versions
5.0.10
5.0.11
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.10.0
5.10.1
5.11.0
5.11.1
+ 35 more Show less
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.2.0
5.3.0
5.4.0
5.4.1
5.4.2
5.4.3.pre.beta0
5.5.0
5.5.0.pre.beta0
5.5.1
5.5.2
5.5.2.pre.beta0
5.6.0
5.6.1
5.7.0
5.7.2
5.8.0
5.8.1
5.9.0
5.9.1
Fixed in
5.19.0
References
Updated Nov 13, 2024 · Source: OSV.dev
CVE-2024-46977
GHSA-8jxr-mccc-mwg8
PYSEC-2024-101
Oct 02, 2024
OpenC3 Path Traversal via screen controller (`GHSL-2024-127`)
High
Network
Low
Low
None
SummaryA path traversal vulnerability inside of Note: This CVE affects all OpenC3 COSMOS Editions ImpactThis issue may lead to Information Disclosure. Affected versions
5.0.10
5.0.11
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.10.0
5.10.1
5.11.0
5.11.1
+ 35 more Show less
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.2.0
5.3.0
5.4.0
5.4.1
5.4.2
5.4.3.pre.beta0
5.5.0
5.5.0.pre.beta0
5.5.1
5.5.2
5.5.2.pre.beta0
5.6.0
5.6.1
5.7.0
5.7.2
5.8.0
5.8.1
5.9.0
5.9.1
Fixed in
5.19.0
References
Updated Oct 31, 2024 · Source: OSV.dev
CVE-2024-43795
GHSA-vfj8-5pj7-2f9g
PYSEC-2024-100
Oct 02, 2024
OpenC3 Cross-site Scripting in Login functionality (`GHSL-2024-128`)
Medium
Network
Low
None
SummaryThe login functionality contains a reflected cross-site scripting (XSS) vulnerability. Note: This CVE only affects Open Source Edition, and not OpenC3 COSMOS Enterprise Edition ImpactThis issue may lead up to Remote Code Execution (RCE). Affected versions
5.0.10
5.0.11
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.10.0
5.10.1
5.11.0
5.11.1
+ 35 more Show less
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.2.0
5.3.0
5.4.0
5.4.1
5.4.2
5.4.3.pre.beta0
5.5.0
5.5.0.pre.beta0
5.5.1
5.5.2
5.5.2.pre.beta0
5.6.0
5.6.1
5.7.0
5.7.2
5.8.0
5.8.1
5.9.0
5.9.1
Fixed in
5.19.0
References
Updated Oct 31, 2024 · Source: OSV.dev |
5.16.0
minor
Dependencies (52)
+ 44 more
Changelog
Compare changes
|
|
5.15.2
patch
8 CVEs
CVE-2026-42088
GHSA-2wvh-87g2-89hr
PYSEC-2026-2245
Apr 23, 2026
OpenC3 COSMOS: Permissions Bypass Provides User Access to Unassigned Administrative Actions via Script Runner Tool
9.6
/ 10
Critical
Network
Low
Low
None
Changed
High
High
None
Vulnerability Type: Execution with Unnecessary Privileges Attack type: Authenticated remote Impact: Data disclosure/manipulation, privilege escalation Affected components: The following docker images: • Openc3inc/openc3-COSMOS-script-runner-api The Script Runner widget allows users to execute Python and Ruby scripts directly from the openc3-COSMOS-script-runner-api container. Because all the docker containers share a network, users can execute specially crafted scripts to bypass the API permissions check and perform administrative actions, including reading and modifying data inside the Redis database, which can be used to read secrets and change COSMOS settings, as well as read and write to the buckets service, which holds configuration, log, and plugin files. These actions are normally only available from the Admin Console or with administrative privileges. Any user with permission to create and run scripts can connect to any service in the docker network. Figure 1: Environment variables, including Redis credentials, found in the Script Runner container A Ruby script is used to expose the Redis username, password, hostname, and port. These credentials might also be found from the source code or through a brute-force attack. Figure 2: A Python script is used to add data to Redis and retrieve the new data
A Python script is then used to create a new entry in the Redis database called Figure 3: The new data found in the Redis database
The new entry was successfully added to the Redis database, as is confirmed by using Figure 4: Uploading file to change the plugin store URL setting Figure 5: The URL file was successfully changed Steps To Reproduce
Recommendations• Limit the permissions of the script runner API to prevent lower level users from performing administrative actions Affected versions
5.0.10
5.0.11
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.10.0
5.10.1
5.11.0
5.11.1
+ 63 more Show less
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.2.0
5.20.0
5.3.0
5.4.0
5.4.1
5.4.2
5.4.3.pre.beta0
5.5.0
5.5.0.pre.beta0
5.5.1
5.5.2
5.5.2.pre.beta0
5.6.0
5.6.1
5.7.0
5.7.2
5.8.0
5.8.1
5.9.0
5.9.1
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.10.5
6.10.6
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
Fixed in
7.0.0-rc3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-42086
GHSA-ffq5-qpvf-xq7x
PYSEC-2026-105
Apr 22, 2026
OpenC3 COSMOS is Vulnerable to Self-XSS Through the Command Sender
4.6
/ 10
Medium
Network
Low
Low
Required
Unchanged
Low
Low
None
SummaryThe Command Sender UI uses an unsafe DetailsThe unsafe PoC
Below example uses ImpactLocal JavaScript execution in the user's browser Affected versions
5.0.10
5.0.11
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.10.0
5.10.1
5.11.0
5.11.1
+ 66 more Show less
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.2.0
5.20.0
5.3.0
5.4.0
5.4.1
5.4.2
5.4.3.pre.beta0
5.5.0
5.5.0.pre.beta0
5.5.1
5.5.2
5.5.2.pre.beta0
5.6.0
5.6.1
5.7.0
5.7.2
5.8.0
5.8.1
5.9.0
5.9.1
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.10.5
6.10.6
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
7.0.0.pre.rc1
7.0.0.pre.rc2
7.0.0.pre.rc3
Fixed in
7.0.0
References
Updated May 29, 2026 · Source: OSV.dev
CVE-2026-42085
GHSA-4jvx-93h3-f45h
PYSEC-2026-2243
Apr 22, 2026
OpenC3 COSMOS allows arbitrary writes to plugins directory via path-traversed config filenames
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
None
SummaryOpenC3 COSMOS contains a design flaw in the DetailsIn function PoC
ImpactModifying the data of other plugins Affected versions
5.0.10
5.0.11
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.10.0
5.10.1
5.11.0
5.11.1
+ 71 more Show less
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.2.0
5.20.0
5.3.0
5.4.0
5.4.1
5.4.2
5.4.3.pre.beta0
5.5.0
5.5.0.pre.beta0
5.5.1
5.5.2
5.5.2.pre.beta0
5.6.0
5.6.1
5.7.0
5.7.2
5.8.0
5.8.1
5.9.0
5.9.1
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
7.0.0
7.0.0.pre.rc1
7.0.0.pre.rc2
7.0.0.pre.rc3
7.0.1
7.1.0
7.1.1
7.2.0
7.2.1
7.3.0
Fixed in
6.10.5
7.0.0-rc3
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-42084
GHSA-wgx6-g857-jjf7
PYSEC-2026-2242
Apr 22, 2026
OpenC3 COSMOS: Hijacked session token can be used to reset password for persistence
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
SummaryThe OpenC3 password change functionality allows a user to change their password without providing the old password, by accepting a valid session token instead. In assumed breach scenarios, this behaviour can be exploited by an attacker who has already obtained a valid session token, to gain persistence in hijacked account (including admin) and prevent legitimate users from accessing the account. DetailsThe design flaw in authentication model (authentication.rb) allows for interchangeable use of password and session tokens for user authentication As old tokens are not revoked upon password reset, an attacker who has obtained a valid session token can continue to authenticate and change the account’s password even after the victim resets it, thereby maintaining persistent control over the compromised account. PoC
ImpactPersistence of an attacker who obtained valid session token and preventing legitimate users from account access Affected versions
5.0.10
5.0.11
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.10.0
5.10.1
5.11.0
5.11.1
+ 71 more Show less
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.2.0
5.20.0
5.3.0
5.4.0
5.4.1
5.4.2
5.4.3.pre.beta0
5.5.0
5.5.0.pre.beta0
5.5.1
5.5.2
5.5.2.pre.beta0
5.6.0
5.6.1
5.7.0
5.7.2
5.8.0
5.8.1
5.9.0
5.9.1
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
7.0.0
7.0.0.pre.rc1
7.0.0.pre.rc2
7.0.0.pre.rc3
7.0.1
7.1.0
7.1.1
7.2.0
7.2.1
7.3.0
Fixed in
6.10.5
7.0.0-rc3
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2025-68271
GHSA-w757-4qv9-mghp
Jan 13, 2026
openc3-api Vulnerable to Unauthenticated Remote Code Execution
10.0
/ 10
Critical
Network
Low
None
None
Changed
High
High
High
SummaryOpenC3 COSMOS contains a critical remote code execution vulnerability reachable through the JSON-RPC API. When a JSON-RPC request uses the string form of certain APIs, attacker-controlled parameter text is parsed into values using String#convert_to_value. For array-like inputs, convert_to_value executes eval(). Because the cmd code path parses the command string before calling authorize(), an unauthenticated attacker can trigger Ruby code execution even though the request ultimately fails authorization (401). Affected versions
5.0.10
5.0.11
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.10.0
5.10.1
5.11.0
5.11.1
+ 58 more Show less
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.2.0
5.20.0
5.3.0
5.4.0
5.4.1
5.4.2
5.4.3.pre.beta0
5.5.0
5.5.0.pre.beta0
5.5.1
5.5.2
5.5.2.pre.beta0
5.6.0
5.6.1
5.7.0
5.7.2
5.8.0
5.8.1
5.9.0
5.9.1
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
Fixed in
6.10.2
References
Updated Feb 03, 2026 · Source: OSV.dev
CVE-2024-47529
GHSA-4xqv-47rm-37mm
PYSEC-2024-121
Oct 02, 2024
OpenC3 stores passwords in clear text (`GHSL-2024-129`)
Medium
Network
Low
None
SummaryOpenC3 COSMOS stores the password of a user unencrypted in the LocalStorage of a web browser. This makes the user password susceptible to exfiltration via Cross-site scripting (see GHSL-2024-128). Note: This CVE only affects Open Source edition, and not OpenC3 COSMOS Enterprise Edition ImpactThis issue may lead to Information Disclosure. Affected versions
5.0.10
5.0.11
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.10.0
5.10.1
5.11.0
5.11.1
+ 35 more Show less
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.2.0
5.3.0
5.4.0
5.4.1
5.4.2
5.4.3.pre.beta0
5.5.0
5.5.0.pre.beta0
5.5.1
5.5.2
5.5.2.pre.beta0
5.6.0
5.6.1
5.7.0
5.7.2
5.8.0
5.8.1
5.9.0
5.9.1
Fixed in
5.19.0
References
Updated Nov 13, 2024 · Source: OSV.dev
CVE-2024-46977
GHSA-8jxr-mccc-mwg8
PYSEC-2024-101
Oct 02, 2024
OpenC3 Path Traversal via screen controller (`GHSL-2024-127`)
High
Network
Low
Low
None
SummaryA path traversal vulnerability inside of Note: This CVE affects all OpenC3 COSMOS Editions ImpactThis issue may lead to Information Disclosure. Affected versions
5.0.10
5.0.11
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.10.0
5.10.1
5.11.0
5.11.1
+ 35 more Show less
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.2.0
5.3.0
5.4.0
5.4.1
5.4.2
5.4.3.pre.beta0
5.5.0
5.5.0.pre.beta0
5.5.1
5.5.2
5.5.2.pre.beta0
5.6.0
5.6.1
5.7.0
5.7.2
5.8.0
5.8.1
5.9.0
5.9.1
Fixed in
5.19.0
References
Updated Oct 31, 2024 · Source: OSV.dev
CVE-2024-43795
GHSA-vfj8-5pj7-2f9g
PYSEC-2024-100
Oct 02, 2024
OpenC3 Cross-site Scripting in Login functionality (`GHSL-2024-128`)
Medium
Network
Low
None
SummaryThe login functionality contains a reflected cross-site scripting (XSS) vulnerability. Note: This CVE only affects Open Source Edition, and not OpenC3 COSMOS Enterprise Edition ImpactThis issue may lead up to Remote Code Execution (RCE). Affected versions
5.0.10
5.0.11
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.10.0
5.10.1
5.11.0
5.11.1
+ 35 more Show less
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.2.0
5.3.0
5.4.0
5.4.1
5.4.2
5.4.3.pre.beta0
5.5.0
5.5.0.pre.beta0
5.5.1
5.5.2
5.5.2.pre.beta0
5.6.0
5.6.1
5.7.0
5.7.2
5.8.0
5.8.1
5.9.0
5.9.1
Fixed in
5.19.0
References
Updated Oct 31, 2024 · Source: OSV.dev |
5.15.2
patch
Dependencies (52)
+ 44 more
Changelog
Compare changes
|
|
5.15.1
patch
8 CVEs
CVE-2026-42088
GHSA-2wvh-87g2-89hr
PYSEC-2026-2245
Apr 23, 2026
OpenC3 COSMOS: Permissions Bypass Provides User Access to Unassigned Administrative Actions via Script Runner Tool
9.6
/ 10
Critical
Network
Low
Low
None
Changed
High
High
None
Vulnerability Type: Execution with Unnecessary Privileges Attack type: Authenticated remote Impact: Data disclosure/manipulation, privilege escalation Affected components: The following docker images: • Openc3inc/openc3-COSMOS-script-runner-api The Script Runner widget allows users to execute Python and Ruby scripts directly from the openc3-COSMOS-script-runner-api container. Because all the docker containers share a network, users can execute specially crafted scripts to bypass the API permissions check and perform administrative actions, including reading and modifying data inside the Redis database, which can be used to read secrets and change COSMOS settings, as well as read and write to the buckets service, which holds configuration, log, and plugin files. These actions are normally only available from the Admin Console or with administrative privileges. Any user with permission to create and run scripts can connect to any service in the docker network. Figure 1: Environment variables, including Redis credentials, found in the Script Runner container A Ruby script is used to expose the Redis username, password, hostname, and port. These credentials might also be found from the source code or through a brute-force attack. Figure 2: A Python script is used to add data to Redis and retrieve the new data
A Python script is then used to create a new entry in the Redis database called Figure 3: The new data found in the Redis database
The new entry was successfully added to the Redis database, as is confirmed by using Figure 4: Uploading file to change the plugin store URL setting Figure 5: The URL file was successfully changed Steps To Reproduce
Recommendations• Limit the permissions of the script runner API to prevent lower level users from performing administrative actions Affected versions
5.0.10
5.0.11
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.10.0
5.10.1
5.11.0
5.11.1
+ 63 more Show less
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.2.0
5.20.0
5.3.0
5.4.0
5.4.1
5.4.2
5.4.3.pre.beta0
5.5.0
5.5.0.pre.beta0
5.5.1
5.5.2
5.5.2.pre.beta0
5.6.0
5.6.1
5.7.0
5.7.2
5.8.0
5.8.1
5.9.0
5.9.1
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.10.5
6.10.6
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
Fixed in
7.0.0-rc3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-42086
GHSA-ffq5-qpvf-xq7x
PYSEC-2026-105
Apr 22, 2026
OpenC3 COSMOS is Vulnerable to Self-XSS Through the Command Sender
4.6
/ 10
Medium
Network
Low
Low
Required
Unchanged
Low
Low
None
SummaryThe Command Sender UI uses an unsafe DetailsThe unsafe PoC
Below example uses ImpactLocal JavaScript execution in the user's browser Affected versions
5.0.10
5.0.11
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.10.0
5.10.1
5.11.0
5.11.1
+ 66 more Show less
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.2.0
5.20.0
5.3.0
5.4.0
5.4.1
5.4.2
5.4.3.pre.beta0
5.5.0
5.5.0.pre.beta0
5.5.1
5.5.2
5.5.2.pre.beta0
5.6.0
5.6.1
5.7.0
5.7.2
5.8.0
5.8.1
5.9.0
5.9.1
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.10.5
6.10.6
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
7.0.0.pre.rc1
7.0.0.pre.rc2
7.0.0.pre.rc3
Fixed in
7.0.0
References
Updated May 29, 2026 · Source: OSV.dev
CVE-2026-42085
GHSA-4jvx-93h3-f45h
PYSEC-2026-2243
Apr 22, 2026
OpenC3 COSMOS allows arbitrary writes to plugins directory via path-traversed config filenames
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
None
SummaryOpenC3 COSMOS contains a design flaw in the DetailsIn function PoC
ImpactModifying the data of other plugins Affected versions
5.0.10
5.0.11
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.10.0
5.10.1
5.11.0
5.11.1
+ 71 more Show less
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.2.0
5.20.0
5.3.0
5.4.0
5.4.1
5.4.2
5.4.3.pre.beta0
5.5.0
5.5.0.pre.beta0
5.5.1
5.5.2
5.5.2.pre.beta0
5.6.0
5.6.1
5.7.0
5.7.2
5.8.0
5.8.1
5.9.0
5.9.1
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
7.0.0
7.0.0.pre.rc1
7.0.0.pre.rc2
7.0.0.pre.rc3
7.0.1
7.1.0
7.1.1
7.2.0
7.2.1
7.3.0
Fixed in
6.10.5
7.0.0-rc3
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-42084
GHSA-wgx6-g857-jjf7
PYSEC-2026-2242
Apr 22, 2026
OpenC3 COSMOS: Hijacked session token can be used to reset password for persistence
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
SummaryThe OpenC3 password change functionality allows a user to change their password without providing the old password, by accepting a valid session token instead. In assumed breach scenarios, this behaviour can be exploited by an attacker who has already obtained a valid session token, to gain persistence in hijacked account (including admin) and prevent legitimate users from accessing the account. DetailsThe design flaw in authentication model (authentication.rb) allows for interchangeable use of password and session tokens for user authentication As old tokens are not revoked upon password reset, an attacker who has obtained a valid session token can continue to authenticate and change the account’s password even after the victim resets it, thereby maintaining persistent control over the compromised account. PoC
ImpactPersistence of an attacker who obtained valid session token and preventing legitimate users from account access Affected versions
5.0.10
5.0.11
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.10.0
5.10.1
5.11.0
5.11.1
+ 71 more Show less
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.2.0
5.20.0
5.3.0
5.4.0
5.4.1
5.4.2
5.4.3.pre.beta0
5.5.0
5.5.0.pre.beta0
5.5.1
5.5.2
5.5.2.pre.beta0
5.6.0
5.6.1
5.7.0
5.7.2
5.8.0
5.8.1
5.9.0
5.9.1
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
7.0.0
7.0.0.pre.rc1
7.0.0.pre.rc2
7.0.0.pre.rc3
7.0.1
7.1.0
7.1.1
7.2.0
7.2.1
7.3.0
Fixed in
6.10.5
7.0.0-rc3
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2025-68271
GHSA-w757-4qv9-mghp
Jan 13, 2026
openc3-api Vulnerable to Unauthenticated Remote Code Execution
10.0
/ 10
Critical
Network
Low
None
None
Changed
High
High
High
SummaryOpenC3 COSMOS contains a critical remote code execution vulnerability reachable through the JSON-RPC API. When a JSON-RPC request uses the string form of certain APIs, attacker-controlled parameter text is parsed into values using String#convert_to_value. For array-like inputs, convert_to_value executes eval(). Because the cmd code path parses the command string before calling authorize(), an unauthenticated attacker can trigger Ruby code execution even though the request ultimately fails authorization (401). Affected versions
5.0.10
5.0.11
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.10.0
5.10.1
5.11.0
5.11.1
+ 58 more Show less
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.2.0
5.20.0
5.3.0
5.4.0
5.4.1
5.4.2
5.4.3.pre.beta0
5.5.0
5.5.0.pre.beta0
5.5.1
5.5.2
5.5.2.pre.beta0
5.6.0
5.6.1
5.7.0
5.7.2
5.8.0
5.8.1
5.9.0
5.9.1
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
Fixed in
6.10.2
References
Updated Feb 03, 2026 · Source: OSV.dev
CVE-2024-47529
GHSA-4xqv-47rm-37mm
PYSEC-2024-121
Oct 02, 2024
OpenC3 stores passwords in clear text (`GHSL-2024-129`)
Medium
Network
Low
None
SummaryOpenC3 COSMOS stores the password of a user unencrypted in the LocalStorage of a web browser. This makes the user password susceptible to exfiltration via Cross-site scripting (see GHSL-2024-128). Note: This CVE only affects Open Source edition, and not OpenC3 COSMOS Enterprise Edition ImpactThis issue may lead to Information Disclosure. Affected versions
5.0.10
5.0.11
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.10.0
5.10.1
5.11.0
5.11.1
+ 35 more Show less
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.2.0
5.3.0
5.4.0
5.4.1
5.4.2
5.4.3.pre.beta0
5.5.0
5.5.0.pre.beta0
5.5.1
5.5.2
5.5.2.pre.beta0
5.6.0
5.6.1
5.7.0
5.7.2
5.8.0
5.8.1
5.9.0
5.9.1
Fixed in
5.19.0
References
Updated Nov 13, 2024 · Source: OSV.dev
CVE-2024-46977
GHSA-8jxr-mccc-mwg8
PYSEC-2024-101
Oct 02, 2024
OpenC3 Path Traversal via screen controller (`GHSL-2024-127`)
High
Network
Low
Low
None
SummaryA path traversal vulnerability inside of Note: This CVE affects all OpenC3 COSMOS Editions ImpactThis issue may lead to Information Disclosure. Affected versions
5.0.10
5.0.11
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.10.0
5.10.1
5.11.0
5.11.1
+ 35 more Show less
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.2.0
5.3.0
5.4.0
5.4.1
5.4.2
5.4.3.pre.beta0
5.5.0
5.5.0.pre.beta0
5.5.1
5.5.2
5.5.2.pre.beta0
5.6.0
5.6.1
5.7.0
5.7.2
5.8.0
5.8.1
5.9.0
5.9.1
Fixed in
5.19.0
References
Updated Oct 31, 2024 · Source: OSV.dev
CVE-2024-43795
GHSA-vfj8-5pj7-2f9g
PYSEC-2024-100
Oct 02, 2024
OpenC3 Cross-site Scripting in Login functionality (`GHSL-2024-128`)
Medium
Network
Low
None
SummaryThe login functionality contains a reflected cross-site scripting (XSS) vulnerability. Note: This CVE only affects Open Source Edition, and not OpenC3 COSMOS Enterprise Edition ImpactThis issue may lead up to Remote Code Execution (RCE). Affected versions
5.0.10
5.0.11
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.10.0
5.10.1
5.11.0
5.11.1
+ 35 more Show less
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.2.0
5.3.0
5.4.0
5.4.1
5.4.2
5.4.3.pre.beta0
5.5.0
5.5.0.pre.beta0
5.5.1
5.5.2
5.5.2.pre.beta0
5.6.0
5.6.1
5.7.0
5.7.2
5.8.0
5.8.1
5.9.0
5.9.1
Fixed in
5.19.0
References
Updated Oct 31, 2024 · Source: OSV.dev |
5.15.1
patch
Dependencies (52)
+ 44 more
Changelog
Compare changes
|
|
5.15.0
minor
8 CVEs
CVE-2026-42088
GHSA-2wvh-87g2-89hr
PYSEC-2026-2245
Apr 23, 2026
OpenC3 COSMOS: Permissions Bypass Provides User Access to Unassigned Administrative Actions via Script Runner Tool
9.6
/ 10
Critical
Network
Low
Low
None
Changed
High
High
None
Vulnerability Type: Execution with Unnecessary Privileges Attack type: Authenticated remote Impact: Data disclosure/manipulation, privilege escalation Affected components: The following docker images: • Openc3inc/openc3-COSMOS-script-runner-api The Script Runner widget allows users to execute Python and Ruby scripts directly from the openc3-COSMOS-script-runner-api container. Because all the docker containers share a network, users can execute specially crafted scripts to bypass the API permissions check and perform administrative actions, including reading and modifying data inside the Redis database, which can be used to read secrets and change COSMOS settings, as well as read and write to the buckets service, which holds configuration, log, and plugin files. These actions are normally only available from the Admin Console or with administrative privileges. Any user with permission to create and run scripts can connect to any service in the docker network. Figure 1: Environment variables, including Redis credentials, found in the Script Runner container A Ruby script is used to expose the Redis username, password, hostname, and port. These credentials might also be found from the source code or through a brute-force attack. Figure 2: A Python script is used to add data to Redis and retrieve the new data
A Python script is then used to create a new entry in the Redis database called Figure 3: The new data found in the Redis database
The new entry was successfully added to the Redis database, as is confirmed by using Figure 4: Uploading file to change the plugin store URL setting Figure 5: The URL file was successfully changed Steps To Reproduce
Recommendations• Limit the permissions of the script runner API to prevent lower level users from performing administrative actions Affected versions
5.0.10
5.0.11
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.10.0
5.10.1
5.11.0
5.11.1
+ 63 more Show less
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.2.0
5.20.0
5.3.0
5.4.0
5.4.1
5.4.2
5.4.3.pre.beta0
5.5.0
5.5.0.pre.beta0
5.5.1
5.5.2
5.5.2.pre.beta0
5.6.0
5.6.1
5.7.0
5.7.2
5.8.0
5.8.1
5.9.0
5.9.1
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.10.5
6.10.6
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
Fixed in
7.0.0-rc3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-42086
GHSA-ffq5-qpvf-xq7x
PYSEC-2026-105
Apr 22, 2026
OpenC3 COSMOS is Vulnerable to Self-XSS Through the Command Sender
4.6
/ 10
Medium
Network
Low
Low
Required
Unchanged
Low
Low
None
SummaryThe Command Sender UI uses an unsafe DetailsThe unsafe PoC
Below example uses ImpactLocal JavaScript execution in the user's browser Affected versions
5.0.10
5.0.11
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.10.0
5.10.1
5.11.0
5.11.1
+ 66 more Show less
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.2.0
5.20.0
5.3.0
5.4.0
5.4.1
5.4.2
5.4.3.pre.beta0
5.5.0
5.5.0.pre.beta0
5.5.1
5.5.2
5.5.2.pre.beta0
5.6.0
5.6.1
5.7.0
5.7.2
5.8.0
5.8.1
5.9.0
5.9.1
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.10.5
6.10.6
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
7.0.0.pre.rc1
7.0.0.pre.rc2
7.0.0.pre.rc3
Fixed in
7.0.0
References
Updated May 29, 2026 · Source: OSV.dev
CVE-2026-42085
GHSA-4jvx-93h3-f45h
PYSEC-2026-2243
Apr 22, 2026
OpenC3 COSMOS allows arbitrary writes to plugins directory via path-traversed config filenames
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
None
SummaryOpenC3 COSMOS contains a design flaw in the DetailsIn function PoC
ImpactModifying the data of other plugins Affected versions
5.0.10
5.0.11
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.10.0
5.10.1
5.11.0
5.11.1
+ 71 more Show less
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.2.0
5.20.0
5.3.0
5.4.0
5.4.1
5.4.2
5.4.3.pre.beta0
5.5.0
5.5.0.pre.beta0
5.5.1
5.5.2
5.5.2.pre.beta0
5.6.0
5.6.1
5.7.0
5.7.2
5.8.0
5.8.1
5.9.0
5.9.1
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
7.0.0
7.0.0.pre.rc1
7.0.0.pre.rc2
7.0.0.pre.rc3
7.0.1
7.1.0
7.1.1
7.2.0
7.2.1
7.3.0
Fixed in
6.10.5
7.0.0-rc3
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-42084
GHSA-wgx6-g857-jjf7
PYSEC-2026-2242
Apr 22, 2026
OpenC3 COSMOS: Hijacked session token can be used to reset password for persistence
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
SummaryThe OpenC3 password change functionality allows a user to change their password without providing the old password, by accepting a valid session token instead. In assumed breach scenarios, this behaviour can be exploited by an attacker who has already obtained a valid session token, to gain persistence in hijacked account (including admin) and prevent legitimate users from accessing the account. DetailsThe design flaw in authentication model (authentication.rb) allows for interchangeable use of password and session tokens for user authentication As old tokens are not revoked upon password reset, an attacker who has obtained a valid session token can continue to authenticate and change the account’s password even after the victim resets it, thereby maintaining persistent control over the compromised account. PoC
ImpactPersistence of an attacker who obtained valid session token and preventing legitimate users from account access Affected versions
5.0.10
5.0.11
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.10.0
5.10.1
5.11.0
5.11.1
+ 71 more Show less
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.2.0
5.20.0
5.3.0
5.4.0
5.4.1
5.4.2
5.4.3.pre.beta0
5.5.0
5.5.0.pre.beta0
5.5.1
5.5.2
5.5.2.pre.beta0
5.6.0
5.6.1
5.7.0
5.7.2
5.8.0
5.8.1
5.9.0
5.9.1
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
7.0.0
7.0.0.pre.rc1
7.0.0.pre.rc2
7.0.0.pre.rc3
7.0.1
7.1.0
7.1.1
7.2.0
7.2.1
7.3.0
Fixed in
6.10.5
7.0.0-rc3
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2025-68271
GHSA-w757-4qv9-mghp
Jan 13, 2026
openc3-api Vulnerable to Unauthenticated Remote Code Execution
10.0
/ 10
Critical
Network
Low
None
None
Changed
High
High
High
SummaryOpenC3 COSMOS contains a critical remote code execution vulnerability reachable through the JSON-RPC API. When a JSON-RPC request uses the string form of certain APIs, attacker-controlled parameter text is parsed into values using String#convert_to_value. For array-like inputs, convert_to_value executes eval(). Because the cmd code path parses the command string before calling authorize(), an unauthenticated attacker can trigger Ruby code execution even though the request ultimately fails authorization (401). Affected versions
5.0.10
5.0.11
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.10.0
5.10.1
5.11.0
5.11.1
+ 58 more Show less
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.2.0
5.20.0
5.3.0
5.4.0
5.4.1
5.4.2
5.4.3.pre.beta0
5.5.0
5.5.0.pre.beta0
5.5.1
5.5.2
5.5.2.pre.beta0
5.6.0
5.6.1
5.7.0
5.7.2
5.8.0
5.8.1
5.9.0
5.9.1
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
Fixed in
6.10.2
References
Updated Feb 03, 2026 · Source: OSV.dev
CVE-2024-47529
GHSA-4xqv-47rm-37mm
PYSEC-2024-121
Oct 02, 2024
OpenC3 stores passwords in clear text (`GHSL-2024-129`)
Medium
Network
Low
None
SummaryOpenC3 COSMOS stores the password of a user unencrypted in the LocalStorage of a web browser. This makes the user password susceptible to exfiltration via Cross-site scripting (see GHSL-2024-128). Note: This CVE only affects Open Source edition, and not OpenC3 COSMOS Enterprise Edition ImpactThis issue may lead to Information Disclosure. Affected versions
5.0.10
5.0.11
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.10.0
5.10.1
5.11.0
5.11.1
+ 35 more Show less
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.2.0
5.3.0
5.4.0
5.4.1
5.4.2
5.4.3.pre.beta0
5.5.0
5.5.0.pre.beta0
5.5.1
5.5.2
5.5.2.pre.beta0
5.6.0
5.6.1
5.7.0
5.7.2
5.8.0
5.8.1
5.9.0
5.9.1
Fixed in
5.19.0
References
Updated Nov 13, 2024 · Source: OSV.dev
CVE-2024-46977
GHSA-8jxr-mccc-mwg8
PYSEC-2024-101
Oct 02, 2024
OpenC3 Path Traversal via screen controller (`GHSL-2024-127`)
High
Network
Low
Low
None
SummaryA path traversal vulnerability inside of Note: This CVE affects all OpenC3 COSMOS Editions ImpactThis issue may lead to Information Disclosure. Affected versions
5.0.10
5.0.11
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.10.0
5.10.1
5.11.0
5.11.1
+ 35 more Show less
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.2.0
5.3.0
5.4.0
5.4.1
5.4.2
5.4.3.pre.beta0
5.5.0
5.5.0.pre.beta0
5.5.1
5.5.2
5.5.2.pre.beta0
5.6.0
5.6.1
5.7.0
5.7.2
5.8.0
5.8.1
5.9.0
5.9.1
Fixed in
5.19.0
References
Updated Oct 31, 2024 · Source: OSV.dev
CVE-2024-43795
GHSA-vfj8-5pj7-2f9g
PYSEC-2024-100
Oct 02, 2024
OpenC3 Cross-site Scripting in Login functionality (`GHSL-2024-128`)
Medium
Network
Low
None
SummaryThe login functionality contains a reflected cross-site scripting (XSS) vulnerability. Note: This CVE only affects Open Source Edition, and not OpenC3 COSMOS Enterprise Edition ImpactThis issue may lead up to Remote Code Execution (RCE). Affected versions
5.0.10
5.0.11
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.10.0
5.10.1
5.11.0
5.11.1
+ 35 more Show less
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.2.0
5.3.0
5.4.0
5.4.1
5.4.2
5.4.3.pre.beta0
5.5.0
5.5.0.pre.beta0
5.5.1
5.5.2
5.5.2.pre.beta0
5.6.0
5.6.1
5.7.0
5.7.2
5.8.0
5.8.1
5.9.0
5.9.1
Fixed in
5.19.0
References
Updated Oct 31, 2024 · Source: OSV.dev |
5.15.0
minor
Dependencies (52)
+ 44 more
Changelog
Compare changes
|
|
5.14.2
patch
8 CVEs
CVE-2026-42088
GHSA-2wvh-87g2-89hr
PYSEC-2026-2245
Apr 23, 2026
OpenC3 COSMOS: Permissions Bypass Provides User Access to Unassigned Administrative Actions via Script Runner Tool
9.6
/ 10
Critical
Network
Low
Low
None
Changed
High
High
None
Vulnerability Type: Execution with Unnecessary Privileges Attack type: Authenticated remote Impact: Data disclosure/manipulation, privilege escalation Affected components: The following docker images: • Openc3inc/openc3-COSMOS-script-runner-api The Script Runner widget allows users to execute Python and Ruby scripts directly from the openc3-COSMOS-script-runner-api container. Because all the docker containers share a network, users can execute specially crafted scripts to bypass the API permissions check and perform administrative actions, including reading and modifying data inside the Redis database, which can be used to read secrets and change COSMOS settings, as well as read and write to the buckets service, which holds configuration, log, and plugin files. These actions are normally only available from the Admin Console or with administrative privileges. Any user with permission to create and run scripts can connect to any service in the docker network. Figure 1: Environment variables, including Redis credentials, found in the Script Runner container A Ruby script is used to expose the Redis username, password, hostname, and port. These credentials might also be found from the source code or through a brute-force attack. Figure 2: A Python script is used to add data to Redis and retrieve the new data
A Python script is then used to create a new entry in the Redis database called Figure 3: The new data found in the Redis database
The new entry was successfully added to the Redis database, as is confirmed by using Figure 4: Uploading file to change the plugin store URL setting Figure 5: The URL file was successfully changed Steps To Reproduce
Recommendations• Limit the permissions of the script runner API to prevent lower level users from performing administrative actions Affected versions
5.0.10
5.0.11
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.10.0
5.10.1
5.11.0
5.11.1
+ 63 more Show less
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.2.0
5.20.0
5.3.0
5.4.0
5.4.1
5.4.2
5.4.3.pre.beta0
5.5.0
5.5.0.pre.beta0
5.5.1
5.5.2
5.5.2.pre.beta0
5.6.0
5.6.1
5.7.0
5.7.2
5.8.0
5.8.1
5.9.0
5.9.1
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.10.5
6.10.6
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
Fixed in
7.0.0-rc3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-42086
GHSA-ffq5-qpvf-xq7x
PYSEC-2026-105
Apr 22, 2026
OpenC3 COSMOS is Vulnerable to Self-XSS Through the Command Sender
4.6
/ 10
Medium
Network
Low
Low
Required
Unchanged
Low
Low
None
SummaryThe Command Sender UI uses an unsafe DetailsThe unsafe PoC
Below example uses ImpactLocal JavaScript execution in the user's browser Affected versions
5.0.10
5.0.11
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.10.0
5.10.1
5.11.0
5.11.1
+ 66 more Show less
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.2.0
5.20.0
5.3.0
5.4.0
5.4.1
5.4.2
5.4.3.pre.beta0
5.5.0
5.5.0.pre.beta0
5.5.1
5.5.2
5.5.2.pre.beta0
5.6.0
5.6.1
5.7.0
5.7.2
5.8.0
5.8.1
5.9.0
5.9.1
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.10.5
6.10.6
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
7.0.0.pre.rc1
7.0.0.pre.rc2
7.0.0.pre.rc3
Fixed in
7.0.0
References
Updated May 29, 2026 · Source: OSV.dev
CVE-2026-42085
GHSA-4jvx-93h3-f45h
PYSEC-2026-2243
Apr 22, 2026
OpenC3 COSMOS allows arbitrary writes to plugins directory via path-traversed config filenames
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
None
SummaryOpenC3 COSMOS contains a design flaw in the DetailsIn function PoC
ImpactModifying the data of other plugins Affected versions
5.0.10
5.0.11
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.10.0
5.10.1
5.11.0
5.11.1
+ 71 more Show less
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.2.0
5.20.0
5.3.0
5.4.0
5.4.1
5.4.2
5.4.3.pre.beta0
5.5.0
5.5.0.pre.beta0
5.5.1
5.5.2
5.5.2.pre.beta0
5.6.0
5.6.1
5.7.0
5.7.2
5.8.0
5.8.1
5.9.0
5.9.1
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
7.0.0
7.0.0.pre.rc1
7.0.0.pre.rc2
7.0.0.pre.rc3
7.0.1
7.1.0
7.1.1
7.2.0
7.2.1
7.3.0
Fixed in
6.10.5
7.0.0-rc3
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-42084
GHSA-wgx6-g857-jjf7
PYSEC-2026-2242
Apr 22, 2026
OpenC3 COSMOS: Hijacked session token can be used to reset password for persistence
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
SummaryThe OpenC3 password change functionality allows a user to change their password without providing the old password, by accepting a valid session token instead. In assumed breach scenarios, this behaviour can be exploited by an attacker who has already obtained a valid session token, to gain persistence in hijacked account (including admin) and prevent legitimate users from accessing the account. DetailsThe design flaw in authentication model (authentication.rb) allows for interchangeable use of password and session tokens for user authentication As old tokens are not revoked upon password reset, an attacker who has obtained a valid session token can continue to authenticate and change the account’s password even after the victim resets it, thereby maintaining persistent control over the compromised account. PoC
ImpactPersistence of an attacker who obtained valid session token and preventing legitimate users from account access Affected versions
5.0.10
5.0.11
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.10.0
5.10.1
5.11.0
5.11.1
+ 71 more Show less
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.2.0
5.20.0
5.3.0
5.4.0
5.4.1
5.4.2
5.4.3.pre.beta0
5.5.0
5.5.0.pre.beta0
5.5.1
5.5.2
5.5.2.pre.beta0
5.6.0
5.6.1
5.7.0
5.7.2
5.8.0
5.8.1
5.9.0
5.9.1
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
7.0.0
7.0.0.pre.rc1
7.0.0.pre.rc2
7.0.0.pre.rc3
7.0.1
7.1.0
7.1.1
7.2.0
7.2.1
7.3.0
Fixed in
6.10.5
7.0.0-rc3
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2025-68271
GHSA-w757-4qv9-mghp
Jan 13, 2026
openc3-api Vulnerable to Unauthenticated Remote Code Execution
10.0
/ 10
Critical
Network
Low
None
None
Changed
High
High
High
SummaryOpenC3 COSMOS contains a critical remote code execution vulnerability reachable through the JSON-RPC API. When a JSON-RPC request uses the string form of certain APIs, attacker-controlled parameter text is parsed into values using String#convert_to_value. For array-like inputs, convert_to_value executes eval(). Because the cmd code path parses the command string before calling authorize(), an unauthenticated attacker can trigger Ruby code execution even though the request ultimately fails authorization (401). Affected versions
5.0.10
5.0.11
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.10.0
5.10.1
5.11.0
5.11.1
+ 58 more Show less
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.2.0
5.20.0
5.3.0
5.4.0
5.4.1
5.4.2
5.4.3.pre.beta0
5.5.0
5.5.0.pre.beta0
5.5.1
5.5.2
5.5.2.pre.beta0
5.6.0
5.6.1
5.7.0
5.7.2
5.8.0
5.8.1
5.9.0
5.9.1
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
Fixed in
6.10.2
References
Updated Feb 03, 2026 · Source: OSV.dev
CVE-2024-47529
GHSA-4xqv-47rm-37mm
PYSEC-2024-121
Oct 02, 2024
OpenC3 stores passwords in clear text (`GHSL-2024-129`)
Medium
Network
Low
None
SummaryOpenC3 COSMOS stores the password of a user unencrypted in the LocalStorage of a web browser. This makes the user password susceptible to exfiltration via Cross-site scripting (see GHSL-2024-128). Note: This CVE only affects Open Source edition, and not OpenC3 COSMOS Enterprise Edition ImpactThis issue may lead to Information Disclosure. Affected versions
5.0.10
5.0.11
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.10.0
5.10.1
5.11.0
5.11.1
+ 35 more Show less
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.2.0
5.3.0
5.4.0
5.4.1
5.4.2
5.4.3.pre.beta0
5.5.0
5.5.0.pre.beta0
5.5.1
5.5.2
5.5.2.pre.beta0
5.6.0
5.6.1
5.7.0
5.7.2
5.8.0
5.8.1
5.9.0
5.9.1
Fixed in
5.19.0
References
Updated Nov 13, 2024 · Source: OSV.dev
CVE-2024-46977
GHSA-8jxr-mccc-mwg8
PYSEC-2024-101
Oct 02, 2024
OpenC3 Path Traversal via screen controller (`GHSL-2024-127`)
High
Network
Low
Low
None
SummaryA path traversal vulnerability inside of Note: This CVE affects all OpenC3 COSMOS Editions ImpactThis issue may lead to Information Disclosure. Affected versions
5.0.10
5.0.11
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.10.0
5.10.1
5.11.0
5.11.1
+ 35 more Show less
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.2.0
5.3.0
5.4.0
5.4.1
5.4.2
5.4.3.pre.beta0
5.5.0
5.5.0.pre.beta0
5.5.1
5.5.2
5.5.2.pre.beta0
5.6.0
5.6.1
5.7.0
5.7.2
5.8.0
5.8.1
5.9.0
5.9.1
Fixed in
5.19.0
References
Updated Oct 31, 2024 · Source: OSV.dev
CVE-2024-43795
GHSA-vfj8-5pj7-2f9g
PYSEC-2024-100
Oct 02, 2024
OpenC3 Cross-site Scripting in Login functionality (`GHSL-2024-128`)
Medium
Network
Low
None
SummaryThe login functionality contains a reflected cross-site scripting (XSS) vulnerability. Note: This CVE only affects Open Source Edition, and not OpenC3 COSMOS Enterprise Edition ImpactThis issue may lead up to Remote Code Execution (RCE). Affected versions
5.0.10
5.0.11
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.10.0
5.10.1
5.11.0
5.11.1
+ 35 more Show less
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.2.0
5.3.0
5.4.0
5.4.1
5.4.2
5.4.3.pre.beta0
5.5.0
5.5.0.pre.beta0
5.5.1
5.5.2
5.5.2.pre.beta0
5.6.0
5.6.1
5.7.0
5.7.2
5.8.0
5.8.1
5.9.0
5.9.1
Fixed in
5.19.0
References
Updated Oct 31, 2024 · Source: OSV.dev |
5.14.2
patch
Dependencies (51)
+ 43 more
Changelog
Compare changes
|
|
5.14.1
patch
8 CVEs
CVE-2026-42088
GHSA-2wvh-87g2-89hr
PYSEC-2026-2245
Apr 23, 2026
OpenC3 COSMOS: Permissions Bypass Provides User Access to Unassigned Administrative Actions via Script Runner Tool
9.6
/ 10
Critical
Network
Low
Low
None
Changed
High
High
None
Vulnerability Type: Execution with Unnecessary Privileges Attack type: Authenticated remote Impact: Data disclosure/manipulation, privilege escalation Affected components: The following docker images: • Openc3inc/openc3-COSMOS-script-runner-api The Script Runner widget allows users to execute Python and Ruby scripts directly from the openc3-COSMOS-script-runner-api container. Because all the docker containers share a network, users can execute specially crafted scripts to bypass the API permissions check and perform administrative actions, including reading and modifying data inside the Redis database, which can be used to read secrets and change COSMOS settings, as well as read and write to the buckets service, which holds configuration, log, and plugin files. These actions are normally only available from the Admin Console or with administrative privileges. Any user with permission to create and run scripts can connect to any service in the docker network. Figure 1: Environment variables, including Redis credentials, found in the Script Runner container A Ruby script is used to expose the Redis username, password, hostname, and port. These credentials might also be found from the source code or through a brute-force attack. Figure 2: A Python script is used to add data to Redis and retrieve the new data
A Python script is then used to create a new entry in the Redis database called Figure 3: The new data found in the Redis database
The new entry was successfully added to the Redis database, as is confirmed by using Figure 4: Uploading file to change the plugin store URL setting Figure 5: The URL file was successfully changed Steps To Reproduce
Recommendations• Limit the permissions of the script runner API to prevent lower level users from performing administrative actions Affected versions
5.0.10
5.0.11
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.10.0
5.10.1
5.11.0
5.11.1
+ 63 more Show less
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.2.0
5.20.0
5.3.0
5.4.0
5.4.1
5.4.2
5.4.3.pre.beta0
5.5.0
5.5.0.pre.beta0
5.5.1
5.5.2
5.5.2.pre.beta0
5.6.0
5.6.1
5.7.0
5.7.2
5.8.0
5.8.1
5.9.0
5.9.1
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.10.5
6.10.6
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
Fixed in
7.0.0-rc3
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-42086
GHSA-ffq5-qpvf-xq7x
PYSEC-2026-105
Apr 22, 2026
OpenC3 COSMOS is Vulnerable to Self-XSS Through the Command Sender
4.6
/ 10
Medium
Network
Low
Low
Required
Unchanged
Low
Low
None
SummaryThe Command Sender UI uses an unsafe DetailsThe unsafe PoC
Below example uses ImpactLocal JavaScript execution in the user's browser Affected versions
5.0.10
5.0.11
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.10.0
5.10.1
5.11.0
5.11.1
+ 66 more Show less
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.2.0
5.20.0
5.3.0
5.4.0
5.4.1
5.4.2
5.4.3.pre.beta0
5.5.0
5.5.0.pre.beta0
5.5.1
5.5.2
5.5.2.pre.beta0
5.6.0
5.6.1
5.7.0
5.7.2
5.8.0
5.8.1
5.9.0
5.9.1
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.10.5
6.10.6
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
7.0.0.pre.rc1
7.0.0.pre.rc2
7.0.0.pre.rc3
Fixed in
7.0.0
References
Updated May 29, 2026 · Source: OSV.dev
CVE-2026-42085
GHSA-4jvx-93h3-f45h
PYSEC-2026-2243
Apr 22, 2026
OpenC3 COSMOS allows arbitrary writes to plugins directory via path-traversed config filenames
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
None
SummaryOpenC3 COSMOS contains a design flaw in the DetailsIn function PoC
ImpactModifying the data of other plugins Affected versions
5.0.10
5.0.11
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.10.0
5.10.1
5.11.0
5.11.1
+ 71 more Show less
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.2.0
5.20.0
5.3.0
5.4.0
5.4.1
5.4.2
5.4.3.pre.beta0
5.5.0
5.5.0.pre.beta0
5.5.1
5.5.2
5.5.2.pre.beta0
5.6.0
5.6.1
5.7.0
5.7.2
5.8.0
5.8.1
5.9.0
5.9.1
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
7.0.0
7.0.0.pre.rc1
7.0.0.pre.rc2
7.0.0.pre.rc3
7.0.1
7.1.0
7.1.1
7.2.0
7.2.1
7.3.0
Fixed in
6.10.5
7.0.0-rc3
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-42084
GHSA-wgx6-g857-jjf7
PYSEC-2026-2242
Apr 22, 2026
OpenC3 COSMOS: Hijacked session token can be used to reset password for persistence
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
SummaryThe OpenC3 password change functionality allows a user to change their password without providing the old password, by accepting a valid session token instead. In assumed breach scenarios, this behaviour can be exploited by an attacker who has already obtained a valid session token, to gain persistence in hijacked account (including admin) and prevent legitimate users from accessing the account. DetailsThe design flaw in authentication model (authentication.rb) allows for interchangeable use of password and session tokens for user authentication As old tokens are not revoked upon password reset, an attacker who has obtained a valid session token can continue to authenticate and change the account’s password even after the victim resets it, thereby maintaining persistent control over the compromised account. PoC
ImpactPersistence of an attacker who obtained valid session token and preventing legitimate users from account access Affected versions
5.0.10
5.0.11
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.10.0
5.10.1
5.11.0
5.11.1
+ 71 more Show less
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.2.0
5.20.0
5.3.0
5.4.0
5.4.1
5.4.2
5.4.3.pre.beta0
5.5.0
5.5.0.pre.beta0
5.5.1
5.5.2
5.5.2.pre.beta0
5.6.0
5.6.1
5.7.0
5.7.2
5.8.0
5.8.1
5.9.0
5.9.1
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.10.2
6.10.3
6.10.4
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
7.0.0
7.0.0.pre.rc1
7.0.0.pre.rc2
7.0.0.pre.rc3
7.0.1
7.1.0
7.1.1
7.2.0
7.2.1
7.3.0
Fixed in
6.10.5
7.0.0-rc3
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2025-68271
GHSA-w757-4qv9-mghp
Jan 13, 2026
openc3-api Vulnerable to Unauthenticated Remote Code Execution
10.0
/ 10
Critical
Network
Low
None
None
Changed
High
High
High
SummaryOpenC3 COSMOS contains a critical remote code execution vulnerability reachable through the JSON-RPC API. When a JSON-RPC request uses the string form of certain APIs, attacker-controlled parameter text is parsed into values using String#convert_to_value. For array-like inputs, convert_to_value executes eval(). Because the cmd code path parses the command string before calling authorize(), an unauthenticated attacker can trigger Ruby code execution even though the request ultimately fails authorization (401). Affected versions
5.0.10
5.0.11
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.10.0
5.10.1
5.11.0
5.11.1
+ 58 more Show less
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.19.0
5.2.0
5.20.0
5.3.0
5.4.0
5.4.1
5.4.2
5.4.3.pre.beta0
5.5.0
5.5.0.pre.beta0
5.5.1
5.5.2
5.5.2.pre.beta0
5.6.0
5.6.1
5.7.0
5.7.2
5.8.0
5.8.1
5.9.0
5.9.1
6.0.0
6.0.1
6.0.2
6.1.0
6.10.0
6.10.1
6.2.0
6.2.1
6.3.0
6.4.0
6.4.1
6.4.2
6.5.0
6.5.1
6.6.0
6.7.0
6.8.0
6.8.1
6.9.0
6.9.1
6.9.2
Fixed in
6.10.2
References
Updated Feb 03, 2026 · Source: OSV.dev
CVE-2024-47529
GHSA-4xqv-47rm-37mm
PYSEC-2024-121
Oct 02, 2024
OpenC3 stores passwords in clear text (`GHSL-2024-129`)
Medium
Network
Low
None
SummaryOpenC3 COSMOS stores the password of a user unencrypted in the LocalStorage of a web browser. This makes the user password susceptible to exfiltration via Cross-site scripting (see GHSL-2024-128). Note: This CVE only affects Open Source edition, and not OpenC3 COSMOS Enterprise Edition ImpactThis issue may lead to Information Disclosure. Affected versions
5.0.10
5.0.11
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.10.0
5.10.1
5.11.0
5.11.1
+ 35 more Show less
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.2.0
5.3.0
5.4.0
5.4.1
5.4.2
5.4.3.pre.beta0
5.5.0
5.5.0.pre.beta0
5.5.1
5.5.2
5.5.2.pre.beta0
5.6.0
5.6.1
5.7.0
5.7.2
5.8.0
5.8.1
5.9.0
5.9.1
Fixed in
5.19.0
References
Updated Nov 13, 2024 · Source: OSV.dev
CVE-2024-46977
GHSA-8jxr-mccc-mwg8
PYSEC-2024-101
Oct 02, 2024
OpenC3 Path Traversal via screen controller (`GHSL-2024-127`)
High
Network
Low
Low
None
SummaryA path traversal vulnerability inside of Note: This CVE affects all OpenC3 COSMOS Editions ImpactThis issue may lead to Information Disclosure. Affected versions
5.0.10
5.0.11
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.10.0
5.10.1
5.11.0
5.11.1
+ 35 more Show less
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.2.0
5.3.0
5.4.0
5.4.1
5.4.2
5.4.3.pre.beta0
5.5.0
5.5.0.pre.beta0
5.5.1
5.5.2
5.5.2.pre.beta0
5.6.0
5.6.1
5.7.0
5.7.2
5.8.0
5.8.1
5.9.0
5.9.1
Fixed in
5.19.0
References
Updated Oct 31, 2024 · Source: OSV.dev
CVE-2024-43795
GHSA-vfj8-5pj7-2f9g
PYSEC-2024-100
Oct 02, 2024
OpenC3 Cross-site Scripting in Login functionality (`GHSL-2024-128`)
Medium
Network
Low
None
SummaryThe login functionality contains a reflected cross-site scripting (XSS) vulnerability. Note: This CVE only affects Open Source Edition, and not OpenC3 COSMOS Enterprise Edition ImpactThis issue may lead up to Remote Code Execution (RCE). Affected versions
5.0.10
5.0.11
5.0.6
5.0.7
5.0.8
5.0.9
5.1.0
5.1.1
5.10.0
5.10.1
5.11.0
5.11.1
+ 35 more Show less
5.11.2
5.11.3
5.12.0
5.13.0
5.14.0
5.14.1
5.14.2
5.15.0
5.15.1
5.15.2
5.16.0
5.16.1
5.16.2
5.17.0
5.17.1
5.18.0
5.2.0
5.3.0
5.4.0
5.4.1
5.4.2
5.4.3.pre.beta0
5.5.0
5.5.0.pre.beta0
5.5.1
5.5.2
5.5.2.pre.beta0
5.6.0
5.6.1
5.7.0
5.7.2
5.8.0
5.8.1
5.9.0
5.9.1
Fixed in
5.19.0
References
Updated Oct 31, 2024 · Source: OSV.dev |
5.14.1
patch
Dependencies (51)
+ 43 more
Changelog
Compare changes
|