PT-2026-97524 · Openc3 · Cosmos

CVE-2026-77602

·

Published

2026-09-23

·

Updated

2026-09-29

CVSS v3.1

9.9

Critical

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions OpenC3 COSMOS versions 5.1.0 through 7.3.0
Description Authenticated non-administrator users can achieve arbitrary code execution on a COSMOS server by writing malicious content into the targets modified/ overlay directory. This is possible because the system reads configuration from this user-writable area before the read-only targets/ tree and subsequently executes the content through several paths.
Technical exploitation occurs via three primary sinks:
  1. Table definitions are processed through ConfigParser, which renders files as ERB (Embedded Ruby) by default, or through GENERIC READ CONVERSION and GENERIC WRITE CONVERSION blocks evaluated by GenericConversion (Ruby and Python) in the cmd-tlm-api container.
  2. Command and telemetry definitions written to targets modified/<TARGET>/cmd tlm/ are processed by PacketConfig in decom microservices, allowing ERB rendering or generic code evaluation upon microservice restart.
  3. Script Runner suite analysis executes procedure files located in targets modified/<TARGET>/procedures/ using the require function in the run suite analysis.rb script.
Attackers can place files in the overlay using the storage-upload endpoint (which exempts targets modified/ from admin checks) or the screen-save endpoint. In the open-source edition, the authorize function ignores permission strings, allowing any authenticated user to exploit these paths.
Recommendations Update OpenC3 COSMOS to version 7.3.0. As a temporary mitigation, restrict access to the storage controller.rb get upload presigned request endpoint and the screens controller.rb create endpoint to administrator users only. Restrict the use of the require function within the Script Runner suite analysis to the script run permission tier.

Exploit

Fix

RCE

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-77602
GHSA-JJQ7-M736-W977

Affected Products

Cosmos