CVE-2026-77601

Source
https://cve.org/CVERecord?id=CVE-2026-77601
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-77601.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2026-77601
Aliases
Published
2026-09-23T18:50:15Z
Modified
2026-09-24T11:30:15Z
Severity
  • 8.8 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
OpenC3 COSMOS: Authenticated OS command injection via the `pypi_url` setting
Details

OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. From 5.12.0 until 7.3.0, an authenticated actor can write the pypi_url setting through set_setting at POST /openc3-api/api, then cause OpenC3::PluginModel.install_phase2 in openc3/lib/openc3/models/plugin_model.rb to interpolate the value into a shell command while installing a plugin with Python dependency metadata. Shell metacharacters in the setting are interpreted by the command shell, allowing arbitrary operating-system commands to run as the openc3 service user with access to Redis and bucket credentials. Open-source deployments permit any authenticated user to reach the affected operations, while Enterprise deployments require an administrator. This issue is fixed in version 7.3.0.

Database specific
{
    "cna_assigner":  "GitHub_M",
    "cwe_ids":  [
        "CWE-78"
    ],
    "osv_generated_from":  "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/77xxx/CVE-2026-77601.json"
}
References

Affected packages

Git / github.com/openc3/cosmos

Affected ranges

Type
GIT
Repo
https://github.com/openc3/cosmos
Events
Database specific
Show details
{
    "extracted_events":  [
        {
            "introduced":  "5.12.0"
        },
        {
            "fixed":  "7.3.0"
        }
    ],
    "source":  "AFFECTED_FIELD"
}

Affected versions

v5.*
v5.12.0
v5.13.0
v5.14.0
v5.14.1
v5.14.2
v5.15.0
v5.15.1
v5.15.2
v5.16.0
v5.16.1
v5.16.2
v5.17.0
v5.17.1
v5.18.0
v5.19.0
v5.20.0
v6.*
v6.0.0
v6.0.1
v6.0.2
v6.1.0
v6.10.0
v6.10.1
v6.10.2
v6.10.3
v6.10.4
v6.2.0
v6.2.1
v6.3.0
v6.4.0
v6.4.1
v6.4.2
v6.5.0
v6.5.1
v6.6.0
v6.7.0
v6.8.1
v6.9.0
v6.9.1
v6.9.2
v7.*
v7.0.0
v7.0.0-rc1
v7.0.0-rc2
v7.0.0-rc3
v7.0.1
v7.1.0
v7.1.1
v7.2.0
v7.2.1

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-77601.json"