CVE Tools

Openc3

7 CVEs tracked since 2025. Since Jun 2025, none of them reached CISA KEV.

Openc3 CVEs per month

Jun 2025 to Jun 2025. Point at a month, or focus the strip and use the arrow keys.
Openc3 CVEs per month, with the share now in CISA KEV
MonthCVEsIn CISA KEV
2025-0670

Products

The products that kept showing up in Openc3's monthly top three, with their CVEs summed over those months.

  1. Cosmos71 month

Latest CVEs

The 15 most recently published vulnerabilities affecting Openc3.

  1. CVE-2026-77602OpenC3 COSMOS: Authenticated remote code execution via the user-writable config overlay (table definitions, cmd/tlm definitions, and script suites)9.9
  2. CVE-2026-77394OpenC3 COSMOS: Stored, cross-user XSS via Telemetry screen BUTTON widget7.6
  3. CVE-2026-77601OpenC3 COSMOS: Authenticated OS command injection via the `pypi_url` setting8.8
  4. CVE-2026-42088OpenC3 COSMOS: Administrative Actions via the Script Runner Tool9.6
  5. CVE-2026-42087OpenC3 COSMOS: SQL Injection in QuestDB Time-Series Data Base9.6
  6. CVE-2026-42086OpenC3 COSMOS: Self-XSS in the Command Sender4.6
  7. CVE-2026-42085OpenC3 COSMOS: Arbitrary write to plugins directory via path-traversed config filenames4.3
  8. CVE-2026-42084OpenC3 COSMOS: Hijacked session token can be used to reset password for persistence8.1
  9. CVE-2025-68271Unauthenticated Remote Code Execution in openc3-api10.0
  10. CVE-2025-28382An issue in the openc3-api/tables endpoint of OpenC3 COSMOS before 6.1.0 allows attackers to execute a directory traversal.7.5
  11. CVE-2025-28386A remote code execution (RCE) vulnerability in the Plugin Management component of OpenC3 COSMOS v6.0.0 allows attackers to execute arbitrary code via uploading a crafted .txt file.9.8
  12. CVE-2025-28380A cross-site scripting (XSS) vulnerability in OpenC3 COSMOS before v6.0.2 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the URL parameter.6.1
  13. CVE-2025-28381A credential leak in OpenC3 COSMOS before v6.0.2 allows attackers to access service credentials as environment variables stored in all containers.7.5
  14. CVE-2025-28389Weak password requirements in OpenC3 COSMOS v6.0.0 allow attackers to bypass authentication via a brute force attack.9.8
  15. CVE-2025-28388OpenC3 COSMOS before v6.0.2 was discovered to contain hardcoded credentials for the Service Account.9.8

The record

Peak rank
#124 in Jun 2025
Busiest month shown
Jun 2025, 7 CVEs
Months with a KEV entry
0 since Jun 2025
Monthly snapshots
1 since 2025
Openc3's full record, month by month

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store