Skip to main content

Vendor/product archive

openc3 / cosmos CVEs

Beta · best-effort

15 CVEs tagged to openc3 / cosmos6 Critical, 3 High, 6 Medium, 0 Low, 0 Unrated.

CVE-2026-42088

Published May 4, 2026

OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. Prior to version 7.0.0-rc3, the Script Runner widget allows…

CVSS 9.6 · Critical
evidence mentions
3
Buzz score
18.9
Vendor/product tagsBeta · best-effort

CVE-2026-42087

Published May 4, 2026

OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. From version 6.7.0 to before version 7.0.0-rc3, a SQL injec…

CVSS 9.6 · Critical
evidence mentions
3
Buzz score
18.9
Vendor/product tagsBeta · best-effort

CVE-2026-42086

Published May 4, 2026

OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. Prior to version 7.0.0, the Command Sender UI uses an unsaf…

CVSS 4.6 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-42085

Published May 4, 2026

OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. Prior to versions 6.10.5 and 7.0.0-rc3, OpenC3 COSMOS conta…

CVSS 4.3 · Medium
evidence mentions
5
Buzz score
22.9
Vendor/product tagsBeta · best-effort

CVE-2026-42084

Published May 4, 2026

OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. Prior to versions 6.10.5 and 7.0.0-rc3, the OpenC3 password…

CVSS 8.1 · High
evidence mentions
4
Buzz score
21.1
Vendor/product tagsBeta · best-effort

CVE-2025-28389

Published Jun 13, 2025

Weak password requirements in OpenC3 COSMOS v6.0.0 allow attackers to bypass authentication via a brute force attack.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2025-28388

Published Jun 13, 2025

OpenC3 COSMOS before v6.0.2 was discovered to contain hardcoded credentials for the Service Account.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2025-28386

Published Jun 13, 2025

A remote code execution (RCE) vulnerability in the Plugin Management component of OpenC3 COSMOS v6.0.0 allows attackers to execute arbitrary code via uploading a crafted .txt file.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2025-28384

Published Jun 13, 2025

An issue in the /script-api/scripts/ endpoint of OpenC3 COSMOS before 6.1.0 allows attackers to execute a directory traversal.

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort

CVE-2025-28382

Published Jun 13, 2025

An issue in the openc3-api/tables endpoint of OpenC3 COSMOS before 6.1.0 allows attackers to execute a directory traversal.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2025-28381

Published Jun 13, 2025

A credential leak in OpenC3 COSMOS before v6.0.2 allows attackers to access service credentials as environment variables stored in all containers.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2025-28380

Published Jun 13, 2025

A cross-site scripting (XSS) vulnerability in OpenC3 COSMOS before v6.0.2 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the URL pa…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-47529

Published Oct 2, 2024

OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. OpenC3 COSMOS stores the password of a user unencrypted in…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-46977

Published Oct 2, 2024

OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. A path traversal vulnerability inside of LocalMode's open_l…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-43795

Published Oct 2, 2024

OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. The login functionality contains a reflected cross-site scr…

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-15 of 15 CVEsPage 1 of 1