Skip to content

Commit 02c6da3

Browse files
committed
GHSA/SYNC: 2 new openc3 advisories
1 parent fb34fed commit 02c6da3

2 files changed

Lines changed: 138 additions & 0 deletions

File tree

‎gems/openc3/CVE-2026-77601.yml‎

Lines changed: 50 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,50 @@
1+
---
2+
gem: openc3
3+
cve: 2026-77601
4+
ghsa: vp3w-52v9-q57f
5+
url: https://nvd.nist.gov/vuln/detail/CVE-2026-77601
6+
title: OpenC3 COSMOS - Authenticated OS command injection via
7+
the `pypi_url` setting
8+
date: 2026-07-11
9+
description: |
10+
## Summary
11+
12+
An authenticated user can execute arbitrary operating system commands
13+
on the `openc3-cosmos-cmd-tlm-api` service. The `pypi_url` setting
14+
is interpolated, unescaped, into a command line that is run through
15+
a shell backtick when a plugin is installed. Shell metacharacters
16+
in the setting value are executed by `/bin/sh`.
17+
18+
## Impact
19+
20+
Arbitrary OS command execution as the `openc3` user (uid 1001) inside
21+
the cmd-tlm-api container. That process holds the Redis/Valkey password
22+
and the bucket (S3) credentials and operates across every scope, so
23+
command execution there exposes stored telemetry, commanding, and
24+
credentials, and allows tampering with any scope.
25+
26+
In the Enterprise edition the prerequisite is the admin role; the
27+
admin already has plugin-driven code execution by design, so the
28+
practical effect there is that a configuration value becomes a shell
29+
command rather than a new privilege boundary being crossed. In the
30+
open-source edition any authenticated user reaches it.
31+
cvss_v3: 8.8
32+
unaffected_versions:
33+
- "< 5.12.0"
34+
patched_versions:
35+
- ">= 7.2.1"
36+
related:
37+
url:
38+
- https://nvd.nist.gov/vuln/detail/CVE-2026-77601
39+
- https://rubygems.org/gems/openc3/versions/7.2.1
40+
- https://github.com/OpenC3/cosmos/releases/tag/v7.2.1
41+
- https://github.com/OpenC3/cosmos/pull/3489
42+
- https://github.com/OpenC3/cosmos/commit/be70d1d836c83c3b084e768e31a399312d4cbe0b
43+
- https://osv.dev/vulnerability/GHSA-vp3w-52v9-q57f
44+
- https://advisories.gitlab.com/gem/openc3/CVE-2026-77601
45+
- https://github.com/OpenC3/cosmos/security/advisories/GHSA-vp3w-52v9-q57f
46+
- https://github.com/advisories/GHSA-vp3w-52v9-q57f
47+
notes: |
48+
- cvss_v3 in GHSA and nvd.nist.gov URLs.
49+
- date from rubygems.org URL
50+
- Found PR#3489 in release 7.2.1 release notes so changed patched_versions.

‎gems/openc3/CVE-2026-77602.yml‎

Lines changed: 88 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,88 @@
1+
---
2+
gem: openc3
3+
cve: 2026-77602
4+
ghsa: jjq7-m736-w977
5+
url: https://nvd.nist.gov/vuln/detail/CVE-2026-77602
6+
title: OpenC3 COSMOS - Authenticated remote code execution via
7+
the user-writable config overlay (table definitions, cmd/tlm
8+
definitions, and script suites)
9+
date: 2026-07-11
10+
description: |
11+
## Summary
12+
13+
COSMOS reads configuration from a user-writable overlay (`targets_modified/`)
14+
before the read-only plugin-installed `targets/` tree, and the config
15+
subsystem executes code on those files: `ConfigParser` renders every
16+
file as ERB by default, a `GENERIC_READ_CONVERSION` /
17+
`GENERIC_WRITE_CONVERSION` block is evaluated as code by
18+
`GenericConversion` (Ruby and Python), and the Script Runner suite
19+
analysis `require`s a procedure file. An authenticated user can write
20+
into `targets_modified/` below the admin tier (the storage-upload
21+
endpoint exempts that area from the admin gate, and the screen-save
22+
endpoint stores its body verbatim there), so the same root cause is
23+
reachable through several features, each giving arbitrary code
24+
execution on a COSMOS server.
25+
26+
Three vulnerable routes were identified, all reachable by an
27+
authenticated non-admin user (in the open-source edition `authorize`
28+
ignores the permission string, so any authenticated user qualifies):
29+
30+
1. **Table definitions** (immediate). `tables#generate|report|load`
31+
reads a definition from `targets_modified/` and ERB-renders it
32+
and evaluates its `GENERIC_*_CONVERSION` block in the
33+
`cmd-tlm-api` container.
34+
35+
2. **Command/telemetry definitions** (persistent). A file written
36+
to `targets_modified/<TARGET>/cmd_tlm/` is overlaid by
37+
`System.setup_targets` and processed by `PacketConfig` in the
38+
decom/multi microservices: ERB-rendered in the Ruby implementation,
39+
and GENERIC-evaluated in both the Ruby and Python implementations
40+
(the Python `ConfigParser` does not run ERB). It executes on
41+
the next microservice (re)start.
42+
43+
3. **Script Runner suites** (immediate). A procedure written to
44+
`targets_modified/<TARGET>/procedures/` is `require`d by the
45+
suite analysis, reachable at the read-only `script_view` tier
46+
through `scripts#body` and `running_script#show` (the analysis
47+
subprocess is spawned when `OPENC3_SERVICE_PASSWORD` is
48+
configured, which it is in the shipped `.env`).
49+
50+
### Impact
51+
52+
Arbitrary code execution as the `openc3` user in the `cmd-tlm-api`
53+
container and the per-target decom microservices and the script-runner.
54+
Those processes hold the Redis and bucket credentials and sit on the
55+
internal service network, so the executed code acts with that authority
56+
over configuration, telemetry, and command data across scopes. The
57+
API is served through Traefik, which the shipped compose binds to
58+
`127.0.0.1:2900`, so a default single-host install is reachable only
59+
from the host; a multi-user deployment exposes the web port, and the
60+
`AV:N` rating reflects that standard remote-operator exposure.
61+
62+
All paths require valid authentication, and the triggering permissions
63+
(`system`/`system_set`/`script_view`) are below the `admin`/`script_run`/
64+
lugin-install tiers where COSMOS gates code execution. In the
65+
open-source edition `authorize` checks only token validity and does
66+
not enforce the permission string, so any authenticated user can
67+
perform these requests.
68+
cvss_v3: 9.9
69+
unaffected_versions:
70+
- "< 5.1.0"
71+
patched_versions:
72+
- ">= 7.2.1"
73+
related:
74+
url:
75+
- https://nvd.nist.gov/vuln/detail/CVE-2026-77602
76+
- https://rubygems.org/gems/openc3/versions/7.2.1
77+
- https://github.com/OpenC3/cosmos/releases/tag/v7.2.1
78+
- https://github.com/OpenC3/cosmos/pull/3488
79+
- https://github.com/OpenC3/cosmos/commit/71943352a28128ef3e7e894319d97a656b5cd4f2
80+
- https://github.com/OpenC3/cosmos/commit/7a1538a4626f82c0d1540fcaa27ffdcbbd71ff81
81+
- https://advisories.gitlab.com/gem/openc3/CVE-2026-77602
82+
- https://osv.dev/vulnerability/GHSA-jjq7-m736-w977
83+
- https://github.com/OpenC3/cosmos/security/advisories/GHSA-jjq7-m736-w977
84+
- https://github.com/advisories/GHSA-jjq7-m736-w977
85+
notes: |
86+
- cvss_v3 in GHSA and nvd.nist.gov URLs.
87+
- date from rubygems.org URL
88+
- Found PR#3488 in release 7.2.1 release notes so changed patched_versions.

0 commit comments

Comments
 (0)