{"id":"CVE-2026-77602","summary":"OpenC3 COSMOS: Authenticated remote code execution via the user-writable config overlay (table definitions, cmd/tlm definitions, and script suites)","details":"OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. From 5.1.0 until 7.3.0, authenticated non-administrator users can write content under targets_modified/ that is later executed by multiple configuration paths below the intended code-execution privilege tier. Table and command or telemetry definitions are processed through ConfigParser, PacketConfig, GENERIC_READ_CONVERSION, or GENERIC_WRITE_CONVERSION, allowing ERB rendering or Ruby and Python evaluation, while openc3-cosmos-script-runner-api/scripts/run_suite_analysis.rb executes suite procedure files through require. Storage uploads, screen saves, and script creation can place content in the overlay, and triggering table processing, a cmd/tlm reload, or suite analysis executes the content in cmd-tlm-api, decom microservices, or Script Runner with access to internal credentials and data. This issue is fixed in version 7.3.0.","aliases":["GHSA-jjq7-m736-w977"],"modified":"2026-09-24T03:47:02.574580462Z","published":"2026-09-23T18:56:16.967Z","database_specific":{"cna_assigner":"GitHub_M","cwe_ids":["CWE-94"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/77xxx/CVE-2026-77602.json"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/77xxx/CVE-2026-77602.json"},{"type":"FIX","url":"https://github.com/OpenC3/cosmos/commit/71943352a28128ef3e7e894319d97a656b5cd4f2"},{"type":"FIX","url":"https://github.com/OpenC3/cosmos/commit/7a1538a4626f82c0d1540fcaa27ffdcbbd71ff81"},{"type":"FIX","url":"https://github.com/OpenC3/cosmos/pull/3488"},{"type":"ADVISORY","url":"https://github.com/OpenC3/cosmos/security/advisories/GHSA-jjq7-m736-w977"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-77602"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/openc3/cosmos","events":[{"introduced":"b39e7b7031bcf5830b9c1ec8dc8f52508bfc17ef"},{"fixed":"92f8c99cc8ed704d2cf747832f09b72d64b6fa65"}],"database_specific":{"extracted_events":[{"introduced":"5.1.0"},{"fixed":"7.3.0"}],"source":"AFFECTED_FIELD"}}],"versions":["v7.2.1","v7.2.0","v7.1.1","v7.1.0","v6.10.4","v7.0.1","v7.0.0","v7.0.0-rc3","v7.0.0-rc2","v7.0.0-rc1","v6.10.3","v6.10.2","v6.10.1","v6.10.0","v6.9.2","v6.9.1","v6.9.0","v6.8.1","v6.7.0","v6.6.0","v6.5.1","v6.5.0","v6.4.2","v6.4.1","v6.4.0","v6.3.0","v6.2.1","v6.2.0","v6.1.0","v6.0.2","v6.0.1","v6.0.0","v5.20.0","v5.19.0","v5.18.0","v5.17.1","v5.17.0","v5.16.2","v5.16.1","v5.16.0","v5.15.2","v5.15.1","v5.15.0","v5.14.2","v5.14.1","v5.14.0","v5.13.0","v5.12.0","v5.11.3","v5.11.2","v5.11.1","v5.11.0","v5.10.1","v5.10.0","v5.9.1","v5.9.0","v5.8.1","v5.8.0","v5.7.2","v5.7.0","v5.6.1","v5.6.0","v5.5.2","v5.5.2-beta0","v5.5.1","v5.5.0","v5.5.0-beta0","v5.4.3-beta0","v5.4.2","v5.4.1","v5.4.0","v5.3.0","v5.2.0","v5.1.1","v5.1.0"],"database_specific":{"source":"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-77602.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"}]}