PT-2026-36882 · Unknown · Openc3 Cosmos

Suffs811

·

Published

2026-05-04

·

Updated

2026-06-03

·

CVE-2026-42088

CVSS v3.1

9.6

Critical

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions OpenC3 COSMOS versions prior to 7.0.0-rc3
Description The Script Runner widget allows users to execute Python and Ruby scripts directly from the 'openc3-COSMOS-script-runner-api' container. Since all Docker containers share a network, users can execute specially crafted scripts to bypass API permissions checks and perform administrative actions. This includes reading and modifying data within the Redis database to access secrets and change settings, as well as reading and writing to the buckets service containing configuration, log, and plugin files. These capabilities are typically restricted to the Admin Console or users with administrative privileges. Any user permitted to create and run scripts can connect to any service within the Docker network.
Recommendations Update to version 7.0.0-rc3.

Exploit

Fix

LPE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-42088

Affected Products

Openc3 Cosmos