OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. From 5.1.0 until 7.3.0, authenticated non-administrator users can write content under targets_modified/ that is later executed by multiple c
Shenlong is analyzing...
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-77601 | 8.8 HIGH | OpenC3 COSMOS: Authenticated OS command injection via the `pypi_url` setting |
| CVE-2026-77394 | 7.6 HIGH | OpenC3 COSMOS: Stored, cross-user XSS via Telemetry screen BUTTON widget |
No comments yet