{"schema_version":1,"title":"openc3 (RubyGems) vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 8 vulnerabilities in openc3 (RubyGems): 2 in the last 7 days and 2 in the last 90 days, 3 of them critical and 0 exploited in the wild. The most recent, CVE-2026-77602, was published on 23 September 2026.","url":"https://junglewise.ai/threats/technologies/openc3","json_url":"https://junglewise.ai/threats/technologies/openc3.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/technologies/openc3","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"technology","counts":{"high":1,"all_time":8,"critical":3,"exploited":0,"last_7_days":2,"last_30_days":2,"last_90_days":2,"last_365_days":5},"latest":[{"cve":"CVE-2026-77602","cvss":9.9,"epss":0.0057,"slug":"cve-2026-77602-openc3-cosmos-authenticated-remote-code-execution-via-config","title":"OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. From 5.1.0 until 7.3","severity":"critical","exploited":false,"published_at":"2026-09-23T19:19:18.55+00:00","url":"https://junglewise.ai/threats/cve-2026-77602-openc3-cosmos-authenticated-remote-code-execution-via-config"},{"cve":"CVE-2026-77601","cvss":8.8,"epss":0.0058,"slug":"cve-2026-77601-openc3-cosmos-authenticated-os-command-injection-via-pypi-url","title":"OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. From 5.12.0 until 7.","severity":"high","exploited":false,"published_at":"2026-09-23T19:19:18.38+00:00","url":"https://junglewise.ai/threats/cve-2026-77601-openc3-cosmos-authenticated-os-command-injection-via-pypi-url"},{"cvss":9.6,"slug":"openc3-cosmos-permissions-bypass-provides-user-access-to-unassigned-7bacf579","title":"OpenC3 COSMOS: Permissions Bypass Provides User Access to Unassigned Administrative Actions via Script Runner Tool","severity":"critical","exploited":false,"published_at":"2026-04-23T14:17:53+00:00","url":"https://junglewise.ai/threats/openc3-cosmos-permissions-bypass-provides-user-access-to-unassigned-7bacf579"},{"cve":"CVE-2026-42087","cvss":9.6,"epss":0.0045,"slug":"cve-2026-42087-openc3-cosmos-sql-injection-in-questdb-time-series-database","title":"OpenC3 COSMOS SQL injection in QuestDB Time-Series Database","severity":"critical","exploited":false,"published_at":"2026-04-23T14:12:02+00:00","url":"https://junglewise.ai/threats/cve-2026-42087-openc3-cosmos-sql-injection-in-questdb-time-series-database"},{"cve":"CVE-2026-42086","cvss":4.6,"epss":0.0029,"slug":"cve-2026-42086-openc3-cosmos-self-xss-in-command-sender","title":"OpenC3 COSMOS Self-XSS in Command Sender","severity":"medium","exploited":false,"published_at":"2026-04-22T22:22:28+00:00","url":"https://junglewise.ai/threats/cve-2026-42086-openc3-cosmos-self-xss-in-command-sender"},{"cve":"CVE-2024-43795","cvss":3.1,"epss":0.0048,"slug":"cve-2024-43795-openc3-cosmos-cross-site-scripting-in-login","title":"PYSEC-2024-100 - OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. The login functional","severity":"low","exploited":false,"published_at":"2024-10-02T20:15:00+00:00","url":"https://junglewise.ai/threats/cve-2024-43795-openc3-cosmos-cross-site-scripting-in-login"},{"cve":"CVE-2024-47529","cvss":3.1,"epss":0.0035,"slug":"cve-2024-47529-openc3-cosmos-cleartext-password-storage-in-browser-localstorage","title":"PYSEC-2024-121 - OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. OpenC3 COSMOS stores","severity":"low","exploited":false,"published_at":"2024-10-02T20:15:00+00:00","url":"https://junglewise.ai/threats/cve-2024-47529-openc3-cosmos-cleartext-password-storage-in-browser-localstorage"},{"cve":"CVE-2024-46977","cvss":3.1,"epss":0.0091,"slug":"cve-2024-46977-openc3-path-traversal-via-screen-controller-ghsl-2024-127","title":"PYSEC-2024-101 - OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. A path traversal vul","severity":"low","exploited":false,"published_at":"2024-10-02T20:15:00+00:00","url":"https://junglewise.ai/threats/cve-2024-46977-openc3-path-traversal-via-screen-controller-ghsl-2024-127"}],"weekly":[{"week":"2026-06-29","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-21","critical":1,"exploited":0,"vulnerabilities":2}],"related":[{"name":"nokogiri (RubyGems)","slug":"nokogiri","vulnerabilities":27,"url":"https://junglewise.ai/threats/technologies/nokogiri"},{"name":"rack (RubyGems)","slug":"rack","vulnerabilities":14,"url":"https://junglewise.ai/threats/technologies/rack"},{"name":"oj (RubyGems)","slug":"oj","vulnerabilities":11,"url":"https://junglewise.ai/threats/technologies/oj"},{"name":"jquery-rails (RubyGems)","slug":"jquery-rails","vulnerabilities":9,"url":"https://junglewise.ai/threats/technologies/jquery-rails"},{"name":"jquery-ui-rails (RubyGems)","slug":"jquery-ui-rails","vulnerabilities":8,"url":"https://junglewise.ai/threats/technologies/jquery-ui-rails"},{"name":"lodash-rails (RubyGems)","slug":"lodash-rails","vulnerabilities":7,"url":"https://junglewise.ai/threats/technologies/lodash-rails"},{"name":"net-imap (RubyGems)","slug":"net-imap","vulnerabilities":7,"url":"https://junglewise.ai/threats/technologies/net-imap"},{"name":"loofah (RubyGems)","slug":"loofah","vulnerabilities":6,"url":"https://junglewise.ai/threats/technologies/loofah"},{"name":"action_text-trix (RubyGems)","slug":"action-text-trix","vulnerabilities":5,"url":"https://junglewise.ai/threats/technologies/action-text-trix"},{"name":"camaleon_cms (RubyGems)","slug":"camaleon-cms","vulnerabilities":4,"url":"https://junglewise.ai/threats/technologies/camaleon-cms"},{"name":"fluentd (RubyGems)","slug":"fluentd","vulnerabilities":4,"url":"https://junglewise.ai/threats/technologies/fluentd"},{"name":"view_component (RubyGems)","slug":"view-component","vulnerabilities":4,"url":"https://junglewise.ai/threats/technologies/view-component"}],"technology":{"hub":true,"name":"openc3 (RubyGems)","slug":"openc3","vendor":{"name":"RubyGems","slug":"rubygems","url":"https://junglewise.ai/threats/vendors/rubygems"},"aliases":[],"homepage":"https://openc3.com/","repo_url":"https://github.com/OpenC3/openc3","description":"An open-source framework for spacecraft and system monitoring and control.","url":"https://junglewise.ai/threats/technologies/openc3"},"most_severe":[{"cve":"CVE-2026-77602","cvss":9.9,"epss":0.0057,"slug":"cve-2026-77602-openc3-cosmos-authenticated-remote-code-execution-via-config","title":"OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. From 5.1.0 until 7.3","severity":"critical","exploited":false,"published_at":"2026-09-23T19:19:18.55+00:00","url":"https://junglewise.ai/threats/cve-2026-77602-openc3-cosmos-authenticated-remote-code-execution-via-config"},{"cve":"CVE-2026-42087","cvss":9.6,"epss":0.0045,"slug":"cve-2026-42087-openc3-cosmos-sql-injection-in-questdb-time-series-database","title":"OpenC3 COSMOS SQL injection in QuestDB Time-Series Database","severity":"critical","exploited":false,"published_at":"2026-04-23T14:12:02+00:00","url":"https://junglewise.ai/threats/cve-2026-42087-openc3-cosmos-sql-injection-in-questdb-time-series-database"},{"cvss":9.6,"slug":"openc3-cosmos-permissions-bypass-provides-user-access-to-unassigned-7bacf579","title":"OpenC3 COSMOS: Permissions Bypass Provides User Access to Unassigned Administrative Actions via Script Runner Tool","severity":"critical","exploited":false,"published_at":"2026-04-23T14:17:53+00:00","url":"https://junglewise.ai/threats/openc3-cosmos-permissions-bypass-provides-user-access-to-unassigned-7bacf579"},{"cve":"CVE-2026-77601","cvss":8.8,"epss":0.0058,"slug":"cve-2026-77601-openc3-cosmos-authenticated-os-command-injection-via-pypi-url","title":"OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. From 5.12.0 until 7.","severity":"high","exploited":false,"published_at":"2026-09-23T19:19:18.38+00:00","url":"https://junglewise.ai/threats/cve-2026-77601-openc3-cosmos-authenticated-os-command-injection-via-pypi-url"},{"cve":"CVE-2026-42086","cvss":4.6,"epss":0.0029,"slug":"cve-2026-42086-openc3-cosmos-self-xss-in-command-sender","title":"OpenC3 COSMOS Self-XSS in Command Sender","severity":"medium","exploited":false,"published_at":"2026-04-22T22:22:28+00:00","url":"https://junglewise.ai/threats/cve-2026-42086-openc3-cosmos-self-xss-in-command-sender"},{"cve":"CVE-2024-46977","cvss":3.1,"epss":0.0091,"slug":"cve-2024-46977-openc3-path-traversal-via-screen-controller-ghsl-2024-127","title":"PYSEC-2024-101 - OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. A path traversal vul","severity":"low","exploited":false,"published_at":"2024-10-02T20:15:00+00:00","url":"https://junglewise.ai/threats/cve-2024-46977-openc3-path-traversal-via-screen-controller-ghsl-2024-127"},{"cve":"CVE-2024-43795","cvss":3.1,"epss":0.0048,"slug":"cve-2024-43795-openc3-cosmos-cross-site-scripting-in-login","title":"PYSEC-2024-100 - OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. The login functional","severity":"low","exploited":false,"published_at":"2024-10-02T20:15:00+00:00","url":"https://junglewise.ai/threats/cve-2024-43795-openc3-cosmos-cross-site-scripting-in-login"},{"cve":"CVE-2024-47529","cvss":3.1,"epss":0.0035,"slug":"cve-2024-47529-openc3-cosmos-cleartext-password-storage-in-browser-localstorage","title":"PYSEC-2024-121 - OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. OpenC3 COSMOS stores","severity":"low","exploited":false,"published_at":"2024-10-02T20:15:00+00:00","url":"https://junglewise.ai/threats/cve-2024-47529-openc3-cosmos-cleartext-password-storage-in-browser-localstorage"}],"generated_at":"2026-09-26T13:07:00.120236+00:00"}