PT-2026-97523 · Unknown · Openc3 Cosmos
CVE-2026-77601
·
Published
2026-09-23
·
Updated
2026-09-23
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
OpenC3 COSMOS versions 5.12.0 through 7.2.9
Description
An authenticated actor can execute arbitrary operating system commands as the
openc3 service user. The issue occurs when the set setting method at the POST /openc3-api/api endpoint is used to write a malicious value to the pypi url variable. This value is subsequently interpolated without proper escaping into a shell command within the OpenC3::PluginModel.install phase2() function located in openc3/lib/openc3/models/plugin model.rb during the installation of a plugin with Python dependency metadata. Shell metacharacters in the pypi url setting are interpreted by /bin/sh, allowing the execution of arbitrary commands. In open-source deployments, any authenticated user can perform these actions, whereas Enterprise deployments require administrator privileges. Successful exploitation provides access to Redis and bucket credentials, potentially exposing stored telemetry and commanding data.Recommendations
Update OpenC3 COSMOS to version 7.3.0.
As a temporary mitigation, restrict access to the
POST /openc3-api/api endpoint or avoid modifying the pypi url setting until the update is applied.Exploit
Fix
OS Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Openc3 Cosmos