Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
50 changes: 50 additions & 0 deletions gems/openc3/CVE-2026-77601.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,50 @@
---
gem: openc3
cve: 2026-77601
ghsa: vp3w-52v9-q57f
url: https://nvd.nist.gov/vuln/detail/CVE-2026-77601
title: OpenC3 COSMOS - Authenticated OS command injection via
the `pypi_url` setting
date: 2026-07-11
description: |
## Summary

An authenticated user can execute arbitrary operating system commands
on the `openc3-cosmos-cmd-tlm-api` service. The `pypi_url` setting
is interpolated, unescaped, into a command line that is run through
a shell backtick when a plugin is installed. Shell metacharacters
in the setting value are executed by `/bin/sh`.

## Impact

Arbitrary OS command execution as the `openc3` user (uid 1001) inside
the cmd-tlm-api container. That process holds the Redis/Valkey password
and the bucket (S3) credentials and operates across every scope, so
command execution there exposes stored telemetry, commanding, and
credentials, and allows tampering with any scope.

In the Enterprise edition the prerequisite is the admin role; the
admin already has plugin-driven code execution by design, so the
practical effect there is that a configuration value becomes a shell
command rather than a new privilege boundary being crossed. In the
open-source edition any authenticated user reaches it.
cvss_v3: 8.8
unaffected_versions:
- "< 5.12.0"
patched_versions:
- ">= 7.2.1"
Comment thread
jasnow marked this conversation as resolved.
related:
url:
- https://nvd.nist.gov/vuln/detail/CVE-2026-77601
- https://rubygems.org/gems/openc3/versions/7.2.1
- https://github.com/OpenC3/cosmos/releases/tag/v7.2.1
- https://github.com/OpenC3/cosmos/pull/3489
- https://github.com/OpenC3/cosmos/commit/be70d1d836c83c3b084e768e31a399312d4cbe0b
- https://osv.dev/vulnerability/GHSA-vp3w-52v9-q57f
- https://advisories.gitlab.com/gem/openc3/CVE-2026-77601
- https://github.com/OpenC3/cosmos/security/advisories/GHSA-vp3w-52v9-q57f
- https://github.com/advisories/GHSA-vp3w-52v9-q57f
notes: |
- cvss_v3 in GHSA and nvd.nist.gov URLs.
- date from rubygems.org URL
- Found PR#3489 in release 7.2.1 release notes so changed patched_versions.
88 changes: 88 additions & 0 deletions gems/openc3/CVE-2026-77602.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,88 @@
---
gem: openc3
cve: 2026-77602
ghsa: jjq7-m736-w977
url: https://nvd.nist.gov/vuln/detail/CVE-2026-77602
title: OpenC3 COSMOS - Authenticated remote code execution via
the user-writable config overlay (table definitions, cmd/tlm
definitions, and script suites)
date: 2026-07-11
description: |
## Summary

COSMOS reads configuration from a user-writable overlay (`targets_modified/`)
before the read-only plugin-installed `targets/` tree, and the config
subsystem executes code on those files: `ConfigParser` renders every
file as ERB by default, a `GENERIC_READ_CONVERSION` /
`GENERIC_WRITE_CONVERSION` block is evaluated as code by
`GenericConversion` (Ruby and Python), and the Script Runner suite
analysis `require`s a procedure file. An authenticated user can write
into `targets_modified/` below the admin tier (the storage-upload
endpoint exempts that area from the admin gate, and the screen-save
endpoint stores its body verbatim there), so the same root cause is
reachable through several features, each giving arbitrary code
execution on a COSMOS server.

Three vulnerable routes were identified, all reachable by an
authenticated non-admin user (in the open-source edition `authorize`
ignores the permission string, so any authenticated user qualifies):

1. **Table definitions** (immediate). `tables#generate|report|load`
reads a definition from `targets_modified/` and ERB-renders it
and evaluates its `GENERIC_*_CONVERSION` block in the
`cmd-tlm-api` container.

2. **Command/telemetry definitions** (persistent). A file written
to `targets_modified/<TARGET>/cmd_tlm/` is overlaid by
`System.setup_targets` and processed by `PacketConfig` in the
decom/multi microservices: ERB-rendered in the Ruby implementation,
and GENERIC-evaluated in both the Ruby and Python implementations
(the Python `ConfigParser` does not run ERB). It executes on
the next microservice (re)start.

3. **Script Runner suites** (immediate). A procedure written to
`targets_modified/<TARGET>/procedures/` is `require`d by the
suite analysis, reachable at the read-only `script_view` tier
through `scripts#body` and `running_script#show` (the analysis
subprocess is spawned when `OPENC3_SERVICE_PASSWORD` is
configured, which it is in the shipped `.env`).

### Impact

Arbitrary code execution as the `openc3` user in the `cmd-tlm-api`
container and the per-target decom microservices and the script-runner.
Those processes hold the Redis and bucket credentials and sit on the
internal service network, so the executed code acts with that authority
over configuration, telemetry, and command data across scopes. The
API is served through Traefik, which the shipped compose binds to
`127.0.0.1:2900`, so a default single-host install is reachable only
from the host; a multi-user deployment exposes the web port, and the
`AV:N` rating reflects that standard remote-operator exposure.

All paths require valid authentication, and the triggering permissions
(`system`/`system_set`/`script_view`) are below the `admin`/`script_run`/
lugin-install tiers where COSMOS gates code execution. In the
open-source edition `authorize` checks only token validity and does
not enforce the permission string, so any authenticated user can
perform these requests.
cvss_v3: 9.9
unaffected_versions:
- "< 5.1.0"
patched_versions:
- ">= 7.2.1"
Comment thread
jasnow marked this conversation as resolved.
related:
url:
- https://nvd.nist.gov/vuln/detail/CVE-2026-77602
- https://rubygems.org/gems/openc3/versions/7.2.1
- https://github.com/OpenC3/cosmos/releases/tag/v7.2.1
- https://github.com/OpenC3/cosmos/pull/3488
- https://github.com/OpenC3/cosmos/commit/71943352a28128ef3e7e894319d97a656b5cd4f2
- https://github.com/OpenC3/cosmos/commit/7a1538a4626f82c0d1540fcaa27ffdcbbd71ff81
- https://advisories.gitlab.com/gem/openc3/CVE-2026-77602
- https://osv.dev/vulnerability/GHSA-jjq7-m736-w977
- https://github.com/OpenC3/cosmos/security/advisories/GHSA-jjq7-m736-w977
- https://github.com/advisories/GHSA-jjq7-m736-w977
notes: |
- cvss_v3 in GHSA and nvd.nist.gov URLs.
- date from rubygems.org URL
- Found PR#3488 in release 7.2.1 release notes so changed patched_versions.
Loading