Junglewise Threat Intelligence

CVE-2025-28382: OpenC3 COSMOS Vulnerable to Directory Traversal via openc3-api/tables endpoint

CVE-2025-28382 · Severity: low · CVSS 3.1 · Published 2025-06-13

Technologies: openc3 (PyPI). Vendors: RubyGems, PyPI.

Executive brief

OpenC3 COSMOS Vulnerable to Directory Traversal via openc3-api/tables endpoint

Affected products

  • RubyGems openc3-cosmos-tool-iframe
  • PyPI openc3

Related threats