VendorsOpenC3cosmosall versions
Vulnerabilities

OpenC3 COSMOS

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

15CVEs
CVE-2025-28386
A remote code execution (RCE) vulnerability in the Plugin Management component of OpenC3 COSMOS v6.0.0 allows attackers to execute arbitrary code via uploading a crafted .txt file.
Published 2025-06-13 · Analyzed
9.8EPSS 0.011
CVE-2025-28388
OpenC3 COSMOS before v6.0.2 was discovered to contain hardcoded credentials for the Service Account.
Published 2025-06-13 · Modified
9.8EPSS 0.006
CVE-2025-28389
Weak password requirements in OpenC3 COSMOS v6.0.0 allow attackers to bypass authentication via a brute force attack.
Published 2025-06-13 · Analyzed
9.8EPSS 0.006
CVE-2026-42088
OpenC3 COSMOS: Administrative Actions via the Script Runner Tool
Published 2026-05-04 · Analyzed
9.6EPSS 0.005
CVE-2026-42087
OpenC3 COSMOS: SQL Injection in QuestDB Time-Series Data Base
Published 2026-05-04 · Analyzed
9.6EPSS 0.004
CVE-2025-28384
An issue in the /script-api/scripts/ endpoint of OpenC3 COSMOS before 6.1.0 allows attackers to execute a directory traversal.
Published 2025-06-13 · Modified
9.1EPSS 0.009
CVE-2026-42084
OpenC3 COSMOS: Hijacked session token can be used to reset password for persistence
Published 2026-05-04 · Analyzed
8.1EPSS 0.004
CVE-2025-28382
An issue in the openc3-api/tables endpoint of OpenC3 COSMOS before 6.1.0 allows attackers to execute a directory traversal.
Published 2025-06-13 · Modified
7.5EPSS 0.009
CVE-2025-28381
A credential leak in OpenC3 COSMOS before v6.0.2 allows attackers to access service credentials as environment variables stored in all containers.
Published 2025-06-13 · Modified
7.5EPSS 0.005
CVE-2024-46977
OpenC3 COSMOS allows a path traversal via screen controller (`GHSL-2024-127`)
Published 2024-10-02 · Modified
6.5EPSS 0.009
CVE-2024-47529
OpenC3 COSMOS uses clear text storage of password/token (`GHSL-2024-129`)
Published 2024-10-02 · Analyzed
6.5EPSS 0.004
CVE-2024-43795
OpenC3 COSMOS vulnerable to cross-site scripting in Login functionality (`GHSL-2024-128`)
Published 2024-10-02 · Modified
6.1EPSS 0.005
CVE-2025-28380
A cross-site scripting (XSS) vulnerability in OpenC3 COSMOS before v6.0.2 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the URL parameter.
Published 2025-06-13 · Modified
6.1EPSS 0.003
CVE-2026-42086
OpenC3 COSMOS: Self-XSS in the Command Sender
Published 2026-05-04 · Analyzed
4.6EPSS 0.003
CVE-2026-42085
OpenC3 COSMOS: Arbitrary write to plugins directory via path-traversed config filenames
Published 2026-05-04 · Analyzed
4.3EPSS 0.004