| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-vp3w-52v9-q57f | OpenC3 COSMOS: Authenticated OS command injection via the `pypi_url` setting |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Wed, 23 Sep 2026 22:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Openc3
Openc3 cosmos |
|
| Vendors & Products |
Openc3
Openc3 cosmos |
Wed, 23 Sep 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 23 Sep 2026 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. From 5.12.0 until 7.3.0, an authenticated actor can write the pypi_url setting through set_setting at POST /openc3-api/api, then cause OpenC3::PluginModel.install_phase2 in openc3/lib/openc3/models/plugin_model.rb to interpolate the value into a shell command while installing a plugin with Python dependency metadata. Shell metacharacters in the setting are interpreted by the command shell, allowing arbitrary operating-system commands to run as the openc3 service user with access to Redis and bucket credentials. Open-source deployments permit any authenticated user to reach the affected operations, while Enterprise deployments require an administrator. This issue is fixed in version 7.3.0. | |
| Title | OpenC3 COSMOS: Authenticated OS command injection via the `pypi_url` setting | |
| Weaknesses | CWE-78 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-09-23T19:28:50.877Z
Reserved: 2026-08-20T20:48:20.507Z
Link: CVE-2026-77601
Updated: 2026-09-23T19:28:48.280Z
Status : Deferred
Published: 2026-09-23T19:19:18.380
Modified: 2026-09-23T20:17:16.027
Link: CVE-2026-77601
No data.
OpenCVE Enrichment
Updated: 2026-09-23T21:45:02Z
Github GHSA