{"id":"CVE-2026-77601","published":"2026-09-23T19:19:18.380","lastModified":"2026-09-23T20:17:16.027","description":"OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. From 5.12.0 until 7.3.0, an authenticated actor can write the pypi_url setting through set_setting at POST /openc3-api/api, then cause OpenC3::PluginModel.install_phase2 in openc3/lib/openc3/models/plugin_model.rb to interpolate the value into a shell command while installing a plugin with Python dependency metadata. Shell metacharacters in the setting are interpreted by the command shell, allowing arbitrary operating-system commands to run as the openc3 service user with access to Redis and bucket credentials. Open-source deployments permit any authenticated user to reach the affected operations, while Enterprise deployments require an administrator. This issue is fixed in version 7.3.0.","cvssScore":8.8,"cvssSeverity":"HIGH","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","cwes":["CWE-78"],"vendors":[],"products":[],"references":[{"url":"https://github.com/OpenC3/cosmos/commit/be70d1d836c83c3b084e768e31a399312d4cbe0b","tags":[]},{"url":"https://github.com/OpenC3/cosmos/pull/3489","tags":[]},{"url":"https://github.com/OpenC3/cosmos/security/advisories/GHSA-vp3w-52v9-q57f","tags":[]},{"url":"https://github.com/OpenC3/cosmos/security/advisories/GHSA-vp3w-52v9-q57f","tags":[]}],"exploitRefs":[{"url":"https://github.com/OpenC3/cosmos/commit/be70d1d836c83c3b084e768e31a399312d4cbe0b","tags":[]},{"url":"https://github.com/OpenC3/cosmos/pull/3489","tags":[]},{"url":"https://github.com/OpenC3/cosmos/security/advisories/GHSA-vp3w-52v9-q57f","tags":[]},{"url":"https://github.com/OpenC3/cosmos/security/advisories/GHSA-vp3w-52v9-q57f","tags":[]}],"hasPoc":true,"ai":{"summary":"The flaw allows an authenticated actor to write a malicious setting that can execute arbitrary shell commands, leading to Remote Code Execution (RCE).","exploitability":"Exploitation is moderately hard as it requires authentication and specific knowledge of the setting to manipulate. Precondition is an authenticated user with write access to the pypi_url setting.","blast_radius":"If exploited, the impact is high, as it can lead to full control over the system, including access to Redis and bucket credentials.","remediation":"Upgrade to OpenC3 version 7.3.0 or later.","detection":"No reliable host or network indicator is derivable from the published description.","tags":["rce","auth-bypass","web"],"model":"qwen2.5:7b-instruct","analyzedAt":"2026-09-29T08:57:16.399Z"}}