Junglewise Threat Intelligence

CVE-2026-42085: OpenC3 COSMOS path traversal in save_tool_config

CVE-2026-42085 · Severity: medium · CVSS 4.3 · Published 2026-04-22

Technologies: openc3 (PyPI), Openc3 Cosmos. Vendors: PyPI, Openc3.

Executive brief

OpenC3 COSMOS, a platform for command and control of spacecraft and other systems, contains a vulnerability that allows users to save configuration files in unauthorized locations. An attacker with low-level access could exploit this to overwrite critical plugin data or create unauthorized file structures. This could lead to the corruption of plugin functionality or the modification of system configurations.

Technical details

A path traversal vulnerability exists in the `save_tool_config()` function within `local_mode.rb`. While the application attempts to mitigate traversal by canonicalizing filenames to absolute paths, it fails to restrict writes to the specific intended subdirectory, allowing files to be saved anywhere within the broader `OPENC3_LOCAL_MODE_PATH` (the `/plugins` directory tree). An authenticated attacker with network access can use `../` sequences in configuration filenames to escape the intended directory and overwrite files belonging to other plugins. This issue is addressed in versions 6.10.5 and 7.0.0-rc3.

Affected products

  • OpenC3 COSMOS < 6.10.5, >= 7.0.0.pre.rc1, < 7.0.0-rc3

Timeline

  • 2026-04-20: disclosed
  • 2026-04-22: advisory: GitHub Advisory published
  • 2026-05-04: other: NVD published

References

Related threats