PT-2026-36882 · Unknown · Openc3 Cosmos
Suffs811
·
Published
2026-05-04
·
Updated
2026-06-03
·
CVE-2026-42088
CVSS v3.1
9.6
Critical
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
OpenC3 COSMOS versions prior to 7.0.0-rc3
Description
The Script Runner widget allows users to execute Python and Ruby scripts directly from the 'openc3-COSMOS-script-runner-api' container. Since all Docker containers share a network, users can execute specially crafted scripts to bypass API permissions checks and perform administrative actions. This includes reading and modifying data within the Redis database to access secrets and change settings, as well as reading and writing to the buckets service containing configuration, log, and plugin files. These capabilities are typically restricted to the Admin Console or users with administrative privileges. Any user permitted to create and run scripts can connect to any service within the Docker network.
Recommendations
Update to version 7.0.0-rc3.
Exploit
Fix
LPE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Openc3 Cosmos