CVE-2026-42086

Source
https://cve.org/CVERecord?id=CVE-2026-42086
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-42086.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2026-42086
Aliases
Published
2026-05-04T17:15:59.239Z
Modified
2026-05-28T03:55:48.348488024Z
Severity
  • 4.6 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N CVSS Calculator
Summary
OpenC3 COSMOS: Self-XSS in the Command Sender
Details

OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. Prior to version 7.0.0, the Command Sender UI uses an unsafe eval() function on array-like command parameters, which allows a user-supplied payload to execute in the browser when sending a command. This creates a self-XSS risk because an attacker can trigger their own script execution in the victim’s session, if allowed to influence the array parameter input, for example via phishing. If successful, an attacker may read or modify data in the authenticated browser context, including session tokens in local storage. This issue has been patched in version 7.0.0.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/42xxx/CVE-2026-42086.json",
    "cwe_ids": [
        "CWE-79"
    ],
    "cna_assigner": "GitHub_M"
}
References

Affected packages

Git / github.com/openc3/cosmos

Affected ranges

Type
GIT
Repo
https://github.com/openc3/cosmos
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed

Affected versions

v3.*
v3.0.0
v3.1.0
v3.1.1
v3.1.2
v3.2.1
v3.3.0
v3.3.1
v3.4.0
v3.4.1
v3.4.2
v3.5.1
v3.6.0
v3.6.1
v3.6.2
v3.7.0
v3.8.0
v3.8.1
v3.8.2
v3.8.3
v3.9.0
v3.9.1
v3.9.2
v4.*
v4.0.0
v4.0.1
v4.0.2
v4.0.3
v4.1.0
v4.1.1
v4.2.3
v4.3.0
v5.*
v5.0.0
v5.0.0-beta.1
v5.0.0.beta2
v5.0.1
v5.0.10
v5.0.11
v5.0.2
v5.0.3
v5.0.4
v5.0.5
v5.0.7
v5.0.8
v5.0.9
v5.1.0
v5.1.1
v5.10.0
v5.10.1
v5.11.0
v5.11.1
v5.11.2
v5.11.3
v5.12.0
v5.13.0
v5.14.0
v5.14.1
v5.14.2
v5.15.0
v5.15.1
v5.15.2
v5.16.0
v5.16.1
v5.16.2
v5.17.0
v5.17.1
v5.18.0
v5.19.0
v5.2.0
v5.20.0
v5.3.0
v5.4.0
v5.4.1
v5.4.2
v5.4.3-beta0
v5.5.0
v5.5.0-beta0
v5.5.1
v5.5.2
v5.5.2-beta0
v5.6.0
v5.6.1
v5.7.0
v5.7.2
v5.8.0
v5.8.1
v5.9.0
v5.9.1
v6.*
v6.0.0
v6.0.1
v6.0.2
v6.1.0
v6.10.0
v6.10.1
v6.10.2
v6.10.3
v6.10.4
v6.2.0
v6.2.1
v6.3.0
v6.4.0
v6.4.1
v6.4.2
v6.5.0
v6.5.1
v6.6.0
v6.7.0
v6.8.1
v6.9.0
v6.9.1
v6.9.2
v7.*
v7.0.0-rc1
v7.0.0-rc2
v7.0.0-rc3

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-42086.json"