Junglewise Threat Intelligence

CVE-2025-28386: PYSEC-2025-149 - A remote code execution (RCE) vulnerability in the Plugin Management component of OpenC3 COSMOS v6.0.0 allows attackers to execute arbitrary

CVE-2025-28386 · Severity: low · CVSS 3.1 · Published 2025-06-13

Technologies: openc3 (PyPI). Vendors: PyPI.

Executive brief

A remote code execution (RCE) vulnerability in the Plugin Management component of OpenC3 COSMOS v6.0.0 allows attackers to execute arbitrary code via uploading a crafted .txt file.

Affected products

  • PyPI openc3

Related threats