OCTOBER 10, 2026
Live Feed
Back to database
Case File

CVE-2026-77601

HIGH · CVSS 8.8 EPSS 0.58% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-23 · Last synced 2026-10-10

CyberRota Analysis

AI-Generated

OpenC3 COSMOS versions 5.12.0 to 7.3.0 are vulnerable to a command injection flaw that allows authenticated users to manipulate the pypi_url setting, leading to arbitrary command execution as the openc3 service user. This vulnerability poses a significant risk, as it can expose sensitive Redis and bucket credentials. Organizations using OpenC3, particularly those with open-source deployments, should prioritize upgrading to version 7.3.0 to mitigate this high-severity threat.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-77601
Severity
HIGH
CVSS
8.8
EPSS
0.58%

Original NVD Description

OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. From 5.12.0 until 7.3.0, an authenticated actor can write the pypi_url setting through set_setting at POST /openc3-api/api, then cause OpenC3::PluginModel.install_phase2 in openc3/lib/openc3/models/plugin_model.rb to interpolate the value into a shell command while installing a plugin with Python dependency metadata. Shell metacharacters in the setting are interpreted by the command shell, allowing arbitrary operating-system commands to run as the openc3 service user with access to Redis and bucket credentials. Open-source deployments permit any authenticated user to reach the affected operations, while Enterprise deployments require an administrator. This issue is fixed in version 7.3.0.