From 02c6da3f6871df8872cdc805e26964f072d3147b Mon Sep 17 00:00:00 2001 From: Al Snow <43523+jasnow@users.noreply.github.com> Date: Thu, 24 Sep 2026 10:24:00 -0400 Subject: [PATCH] GHSA/SYNC: 2 new openc3 advisories --- gems/openc3/CVE-2026-77601.yml | 50 +++++++++++++++++++ gems/openc3/CVE-2026-77602.yml | 88 ++++++++++++++++++++++++++++++++++ 2 files changed, 138 insertions(+) create mode 100644 gems/openc3/CVE-2026-77601.yml create mode 100644 gems/openc3/CVE-2026-77602.yml diff --git a/gems/openc3/CVE-2026-77601.yml b/gems/openc3/CVE-2026-77601.yml new file mode 100644 index 0000000000..efc778cc8e --- /dev/null +++ b/gems/openc3/CVE-2026-77601.yml @@ -0,0 +1,50 @@ +--- +gem: openc3 +cve: 2026-77601 +ghsa: vp3w-52v9-q57f +url: https://nvd.nist.gov/vuln/detail/CVE-2026-77601 +title: OpenC3 COSMOS - Authenticated OS command injection via + the `pypi_url` setting +date: 2026-07-11 +description: | + ## Summary + + An authenticated user can execute arbitrary operating system commands + on the `openc3-cosmos-cmd-tlm-api` service. The `pypi_url` setting + is interpolated, unescaped, into a command line that is run through + a shell backtick when a plugin is installed. Shell metacharacters + in the setting value are executed by `/bin/sh`. + + ## Impact + + Arbitrary OS command execution as the `openc3` user (uid 1001) inside + the cmd-tlm-api container. That process holds the Redis/Valkey password + and the bucket (S3) credentials and operates across every scope, so + command execution there exposes stored telemetry, commanding, and + credentials, and allows tampering with any scope. + + In the Enterprise edition the prerequisite is the admin role; the + admin already has plugin-driven code execution by design, so the + practical effect there is that a configuration value becomes a shell + command rather than a new privilege boundary being crossed. In the + open-source edition any authenticated user reaches it. +cvss_v3: 8.8 +unaffected_versions: + - "< 5.12.0" +patched_versions: + - ">= 7.2.1" +related: + url: + - https://nvd.nist.gov/vuln/detail/CVE-2026-77601 + - https://rubygems.org/gems/openc3/versions/7.2.1 + - https://github.com/OpenC3/cosmos/releases/tag/v7.2.1 + - https://github.com/OpenC3/cosmos/pull/3489 + - https://github.com/OpenC3/cosmos/commit/be70d1d836c83c3b084e768e31a399312d4cbe0b + - https://osv.dev/vulnerability/GHSA-vp3w-52v9-q57f + - https://advisories.gitlab.com/gem/openc3/CVE-2026-77601 + - https://github.com/OpenC3/cosmos/security/advisories/GHSA-vp3w-52v9-q57f + - https://github.com/advisories/GHSA-vp3w-52v9-q57f +notes: | + - cvss_v3 in GHSA and nvd.nist.gov URLs. + - date from rubygems.org URL + - Found PR#3489 in release 7.2.1 release notes so changed patched_versions. diff --git a/gems/openc3/CVE-2026-77602.yml b/gems/openc3/CVE-2026-77602.yml new file mode 100644 index 0000000000..074da31945 --- /dev/null +++ b/gems/openc3/CVE-2026-77602.yml @@ -0,0 +1,88 @@ +--- +gem: openc3 +cve: 2026-77602 +ghsa: jjq7-m736-w977 +url: https://nvd.nist.gov/vuln/detail/CVE-2026-77602 +title: OpenC3 COSMOS - Authenticated remote code execution via + the user-writable config overlay (table definitions, cmd/tlm + definitions, and script suites) +date: 2026-07-11 +description: | + ## Summary + + COSMOS reads configuration from a user-writable overlay (`targets_modified/`) + before the read-only plugin-installed `targets/` tree, and the config + subsystem executes code on those files: `ConfigParser` renders every + file as ERB by default, a `GENERIC_READ_CONVERSION` / + `GENERIC_WRITE_CONVERSION` block is evaluated as code by + `GenericConversion` (Ruby and Python), and the Script Runner suite + analysis `require`s a procedure file. An authenticated user can write + into `targets_modified/` below the admin tier (the storage-upload + endpoint exempts that area from the admin gate, and the screen-save + endpoint stores its body verbatim there), so the same root cause is + reachable through several features, each giving arbitrary code + execution on a COSMOS server. + + Three vulnerable routes were identified, all reachable by an + authenticated non-admin user (in the open-source edition `authorize` + ignores the permission string, so any authenticated user qualifies): + + 1. **Table definitions** (immediate). `tables#generate|report|load` + reads a definition from `targets_modified/` and ERB-renders it + and evaluates its `GENERIC_*_CONVERSION` block in the + `cmd-tlm-api` container. + + 2. **Command/telemetry definitions** (persistent). A file written + to `targets_modified//cmd_tlm/` is overlaid by + `System.setup_targets` and processed by `PacketConfig` in the + decom/multi microservices: ERB-rendered in the Ruby implementation, + and GENERIC-evaluated in both the Ruby and Python implementations + (the Python `ConfigParser` does not run ERB). It executes on + the next microservice (re)start. + + 3. **Script Runner suites** (immediate). A procedure written to + `targets_modified//procedures/` is `require`d by the + suite analysis, reachable at the read-only `script_view` tier + through `scripts#body` and `running_script#show` (the analysis + subprocess is spawned when `OPENC3_SERVICE_PASSWORD` is + configured, which it is in the shipped `.env`). + + ### Impact + + Arbitrary code execution as the `openc3` user in the `cmd-tlm-api` + container and the per-target decom microservices and the script-runner. + Those processes hold the Redis and bucket credentials and sit on the + internal service network, so the executed code acts with that authority + over configuration, telemetry, and command data across scopes. The + API is served through Traefik, which the shipped compose binds to + `127.0.0.1:2900`, so a default single-host install is reachable only + from the host; a multi-user deployment exposes the web port, and the + `AV:N` rating reflects that standard remote-operator exposure. + + All paths require valid authentication, and the triggering permissions + (`system`/`system_set`/`script_view`) are below the `admin`/`script_run`/ + lugin-install tiers where COSMOS gates code execution. In the + open-source edition `authorize` checks only token validity and does + not enforce the permission string, so any authenticated user can + perform these requests. +cvss_v3: 9.9 +unaffected_versions: + - "< 5.1.0" +patched_versions: + - ">= 7.2.1" +related: + url: + - https://nvd.nist.gov/vuln/detail/CVE-2026-77602 + - https://rubygems.org/gems/openc3/versions/7.2.1 + - https://github.com/OpenC3/cosmos/releases/tag/v7.2.1 + - https://github.com/OpenC3/cosmos/pull/3488 + - https://github.com/OpenC3/cosmos/commit/71943352a28128ef3e7e894319d97a656b5cd4f2 + - https://github.com/OpenC3/cosmos/commit/7a1538a4626f82c0d1540fcaa27ffdcbbd71ff81 + - https://advisories.gitlab.com/gem/openc3/CVE-2026-77602 + - https://osv.dev/vulnerability/GHSA-jjq7-m736-w977 + - https://github.com/OpenC3/cosmos/security/advisories/GHSA-jjq7-m736-w977 + - https://github.com/advisories/GHSA-jjq7-m736-w977 +notes: | + - cvss_v3 in GHSA and nvd.nist.gov URLs. + - date from rubygems.org URL + - Found PR#3488 in release 7.2.1 release notes so changed patched_versions.