PT-2026-97522 · Unknown · Openc3 Cosmos
CVE-2026-77394
·
Published
2026-09-23
·
Updated
2026-09-23
CVSS v3.1
7.6
High
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
OpenC3 COSMOS versions 5.0.6 through 7.2.0
Description
An authenticated actor with
system set permission can perform a stored cross-user cross-site scripting (XSS) attack. By sending a request to the 'POST /openc3-api/screen' endpoint, an attacker can store a shared screen containing a BUTTON widget with a malicious action. This action is processed by the ButtonWidget.vue component using the eval() function when another operator activates the button in their browser session. The executed script runs within the COSMOS origin and can access localStorage.openc3Token, enabling the theft of the victim's bearer token, account takeover, and unauthorized actions using the victim's privileges. A permissive Content Security Policy (CSP) that allows unsafe-inline and unsafe-eval contributes to the execution of the script.Recommendations
Update OpenC3 COSMOS to version 7.3.0.
As a temporary mitigation, restrict the use of the
system set permission to trusted users only.
Tighten the Content Security Policy (CSP) in openc3-traefik/traefik.yaml by removing unsafe-inline and unsafe-eval to prevent the execution of injected scripts.Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Openc3 Cosmos