{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3aopenc3cosmos/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:openc3:cosmos:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":9.9,"id":"CVE-2026-77602"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["COSMOS (5.1.0-7.2.1)","COSMOS (7.2.0)","@openc3/vue-common (\u003e= 5.0.6, \u003c= 7.2.1)"],"_cs_severities":["critical"],"_cs_tags":["rce","authenticated-rce","openc3","cosmos","xss","web-vulnerability","session-hijacking"],"_cs_type":"advisory","_cs_vendors":["OpenC3"],"content_html":"\u003cp\u003eOpenC3 COSMOS contains a critical vulnerability (CVE-2026-77602) allowing authenticated remote code execution (RCE). The application processes configuration files from a user-writable overlay directory (\u003ccode\u003etargets_modified/\u003c/code\u003e) before the system-defined read-only \u003ccode\u003etargets/\u003c/code\u003e tree. Because the configuration subsystem treats these user-controlled files as templates and executable code, an attacker can leverage several API endpoints - including screen saving, table generation, and storage uploads - to place malicious files in the overlay. These files are then executed via ERB rendering, generic code conversion blocks, or direct inclusion by the script runner suite analysis.\u003c/p\u003e\n\u003cp\u003eThe vulnerability affects versions 5.1.0 through 7.2.1. In the open-source edition, authorization checks fail to enforce permission strings, allowing any authenticated user to exploit the flaw. Successful exploitation results in arbitrary code execution as the \u003ccode\u003eopenc3\u003c/code\u003e user within the \u003ccode\u003ecmd-tlm-api\u003c/code\u003e container or target-specific microservices, granting the attacker control over configuration, telemetry, and command data.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker obtains valid authentication credentials for the COSMOS API.\u003c/li\u003e\n\u003cli\u003eAttacker interacts with the \u003ccode\u003e/screen\u003c/code\u003e endpoint or \u003ccode\u003estorage_controller\u003c/code\u003e to bypass admin-gated file writing checks.\u003c/li\u003e\n\u003cli\u003eAttacker crafts a malicious configuration file containing an ERB template or a \u003ccode\u003eGENERIC_WRITE_CONVERSION\u003c/code\u003e code block.\u003c/li\u003e\n\u003cli\u003eAttacker writes the malicious file into the \u003ccode\u003etargets_modified/\u003c/code\u003e directory via authorized API calls.\u003c/li\u003e\n\u003cli\u003eAttacker triggers the vulnerability by calling \u003ccode\u003etables#generate\u003c/code\u003e, \u003ccode\u003etables#report\u003c/code\u003e, or initiating a \u003ccode\u003escript_view\u003c/code\u003e operation.\u003c/li\u003e\n\u003cli\u003eCOSMOS configuration parser reads the malicious file from \u003ccode\u003etargets_modified/\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eThe application engine executes the embedded Ruby or Python code within the \u003ccode\u003ecmd-tlm-api\u003c/code\u003e or script runner container.\u003c/li\u003e\n\u003cli\u003eAttacker gains persistent or immediate arbitrary code execution within the container environment.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe vulnerability allows arbitrary code execution as the \u003ccode\u003eopenc3\u003c/code\u003e user. Compromised containers hold Redis and bucket credentials and reside on the internal service network, enabling the attacker to manipulate telemetry, commands, and configurations. In default multi-user deployments, the API is exposed, and even in single-host deployments, the service is reachable via local network paths.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritize patching and restrict access to the affected endpoints.\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade to a version of OpenC3 COSMOS containing the fix (post-v7.2.1).\u003c/li\u003e\n\u003cli\u003eRestrict access to API endpoints involved in configuration and script management, specifically \u003ccode\u003e/screen\u003c/code\u003e, \u003ccode\u003etables/\u003c/code\u003e, and \u003ccode\u003escripts/\u003c/code\u003e, to trusted administrative users.\u003c/li\u003e\n\u003cli\u003eAudit the \u003ccode\u003etargets_modified/\u003c/code\u003e directory for any unexpected or suspicious file modifications.\u003c/li\u003e\n\u003cli\u003eMonitor API access logs for anomalous POST requests to configuration-related endpoints originating from non-administrative service accounts.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-24T01:57:22Z","date_published":"2026-09-23T19:56:36Z","id":"https://feed.craftedsignal.io/briefs/2026-09-openc3-rce/","summary":"Authenticated users can achieve arbitrary code execution in OpenC3 COSMOS by writing malicious payloads into user-writable configuration overlays that are subsequently rendered as code by the application.","title":"OpenC3 COSMOS Authenticated Remote Code Execution","url":"https://feed.craftedsignal.io/briefs/2026-09-openc3-rce/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:openc3:cosmos:*:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}