CPE
Authenticated users can achieve arbitrary code execution in OpenC3 COSMOS by writing malicious payloads into user-writable configuration overlays that are subsequently rendered as code by the application.