OpenC3 / Cosmos
19 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-77602 | OpenC3 COSMOS: Authenticated remote code execution via the user-writable config overlay (table definitions, cmd/tlm definitions, and script suites) | CRITICAL | 9.9 | Sep 23, 2026 |
| CVE-2026-77394 | OpenC3 COSMOS: Stored, cross-user XSS via Telemetry screen BUTTON widget | HIGH | 7.6 | Sep 23, 2026 |
| CVE-2026-77601 | OpenC3 COSMOS: Authenticated OS command injection via the `pypi_url` setting | HIGH | 8.8 | Sep 23, 2026 |
| CVE-2026-42088 | OpenC3 COSMOS: Administrative Actions via the Script Runner Tool | CRITICAL | 9.6 | May 4, 2026 |
| CVE-2026-42087 | OpenC3 COSMOS: SQL Injection in QuestDB Time-Series Data Base | CRITICAL | 9.6 | May 4, 2026 |
| CVE-2026-42086 | OpenC3 COSMOS: Self-XSS in the Command Sender | MEDIUM | 4.6 | May 4, 2026 |
| CVE-2026-42085 | OpenC3 COSMOS: Arbitrary write to plugins directory via path-traversed config filenames | MEDIUM | 4.3 | May 4, 2026 |
| CVE-2026-42084 | OpenC3 COSMOS: Hijacked session token can be used to reset password for persistence | HIGH | 8.1 | May 4, 2026 |
| CVE-2025-68271 | Unauthenticated Remote Code Execution in openc3-api | CRITICAL | 10.0 | Jan 13, 2026 |
| CVE-2025-28389 | Weak password requirements in OpenC3 COSMOS v6.0.0 allow attackers to bypass authentication via a brute force attack. | CRITICAL | 9.8 | Jun 13, 2025 |
| CVE-2025-28388 | OpenC3 COSMOS before v6.0.2 was discovered to contain hardcoded credentials for the Service Account. | CRITICAL | 9.8 | Jun 13, 2025 |
| CVE-2025-28386 | A remote code execution (RCE) vulnerability in the Plugin Management component of OpenC3 COSMOS v6.0.0 allows attackers to execute arbitrary code via uploading… | CRITICAL | 9.8 | Jun 13, 2025 |
| CVE-2025-28384 | An issue in the /script-api/scripts/ endpoint of OpenC3 COSMOS before 6.1.0 allows attackers to execute a directory traversal. | CRITICAL | 9.1 | Jun 13, 2025 |
| CVE-2025-28382 | An issue in the openc3-api/tables endpoint of OpenC3 COSMOS before 6.1.0 allows attackers to execute a directory traversal. | HIGH | 7.5 | Jun 13, 2025 |
| CVE-2025-28381 | A credential leak in OpenC3 COSMOS before v6.0.2 allows attackers to access service credentials as environment variables stored in all containers. | HIGH | 7.5 | Jun 13, 2025 |
| CVE-2025-28380 | A cross-site scripting (XSS) vulnerability in OpenC3 COSMOS before v6.0.2 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted pay… | MEDIUM | 6.1 | Jun 13, 2025 |
| CVE-2024-47529 | OpenC3 COSMOS uses clear text storage of password/token (`GHSL-2024-129`) | MEDIUM | 5.9 | Oct 2, 2024 |
| CVE-2024-46977 | OpenC3 COSMOS allows a path traversal via screen controller (`GHSL-2024-127`) | HIGH | 7.1 | Oct 2, 2024 |
| CVE-2024-43795 | OpenC3 COSMOS vulnerable to cross-site scripting in Login functionality (`GHSL-2024-128`) | MEDIUM | 5.1 | Oct 2, 2024 |
Showing 1 to 19 of 19 CVEs