PT-2026-97524 · Openc3 · Cosmos
CVE-2026-77602
·
Published
2026-09-23
·
Updated
2026-09-29
CVSS v3.1
9.9
Critical
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
OpenC3 COSMOS versions 5.1.0 through 7.3.0
Description
Authenticated non-administrator users can achieve arbitrary code execution on a COSMOS server by writing malicious content into the
targets modified/ overlay directory. This is possible because the system reads configuration from this user-writable area before the read-only targets/ tree and subsequently executes the content through several paths.Technical exploitation occurs via three primary sinks:
- Table definitions are processed through
ConfigParser, which renders files as ERB (Embedded Ruby) by default, or throughGENERIC READ CONVERSIONandGENERIC WRITE CONVERSIONblocks evaluated byGenericConversion(Ruby and Python) in thecmd-tlm-apicontainer. - Command and telemetry definitions written to
targets modified/<TARGET>/cmd tlm/are processed byPacketConfigin decom microservices, allowing ERB rendering or generic code evaluation upon microservice restart. - Script Runner suite analysis executes procedure files located in
targets modified/<TARGET>/procedures/using therequirefunction in therun suite analysis.rbscript.
Attackers can place files in the overlay using the storage-upload endpoint (which exempts
targets modified/ from admin checks) or the screen-save endpoint. In the open-source edition, the authorize function ignores permission strings, allowing any authenticated user to exploit these paths.Recommendations
Update OpenC3 COSMOS to version 7.3.0.
As a temporary mitigation, restrict access to the
storage controller.rb get upload presigned request endpoint and the screens controller.rb create endpoint to administrator users only.
Restrict the use of the require function within the Script Runner suite analysis to the script run permission tier.Exploit
Fix
RCE
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cosmos