Security Vulnerability in OpenC3 COSMOS by OpenC3
CVE-2026-77601
8.8HIGH
What is CVE-2026-77601?
OpenC3 COSMOS versions from 5.12.0 to 7.3.0 are susceptible to a command injection vulnerability. Authenticated users can manipulate the pypi_url setting via a POST request to /openc3-api/api, leading to the execution of arbitrary operating-system commands during plugin installations. This occurs due to improper handling of shell metacharacters, which can be exploited by both open-source and Enterprise deployments, potentially compromising service user permissions and exposing sensitive data.
Affected Version(s)
cosmos >= 5.12.0, < 7.3.0
