PT-2026-97522 · Unknown · Openc3 Cosmos

CVE-2026-77394

·

Published

2026-09-23

·

Updated

2026-09-23

CVSS v3.1

7.6

High

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:N
Name of the Vulnerable Software and Affected Versions OpenC3 COSMOS versions 5.0.6 through 7.2.0
Description An authenticated actor with system set permission can perform a stored cross-user cross-site scripting (XSS) attack. By sending a request to the 'POST /openc3-api/screen' endpoint, an attacker can store a shared screen containing a BUTTON widget with a malicious action. This action is processed by the ButtonWidget.vue component using the eval() function when another operator activates the button in their browser session. The executed script runs within the COSMOS origin and can access localStorage.openc3Token, enabling the theft of the victim's bearer token, account takeover, and unauthorized actions using the victim's privileges. A permissive Content Security Policy (CSP) that allows unsafe-inline and unsafe-eval contributes to the execution of the script.
Recommendations Update OpenC3 COSMOS to version 7.3.0. As a temporary mitigation, restrict the use of the system set permission to trusted users only. Tighten the Content Security Policy (CSP) in openc3-traefik/traefik.yaml by removing unsafe-inline and unsafe-eval to prevent the execution of injected scripts.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-77394
GHSA-GVF2-2RH5-MPGF

Affected Products

Openc3 Cosmos