Impact
OpenC3 COSMOS allows authenticated non‑administrator users to write arbitrary content under the overlay directory targets_modified/. That content is later parsed by configuration parsers, ERB templates, and Ruby/Python evaluation hooks, which results in the execution of arbitrary code. The vulnerability enables attackers to run shell commands, read or modify internal configuration files, and access credentials stored by COSMOS microservices, thereby compromising confidentiality, integrity, and availability of the entire COSMOS deployment.
Affected Systems
The affected product is OpenC3 COSMOS version 5.1.0 through 7.2.x. All releases prior to 7.3.0 contain the flaw and do not restrict the overlay write and execution privileges for non‑administrator users.
Risk and Exploitability
The CVSS score of 9.9 indicates critical severity. The EPSS score is not available, but the lack of a KEV listing does not diminish the vulnerability's inherent risk. An attacker only needs a legitimate non‑administrator COSMOS account and the ability to write to the overlay. After the write, triggering a table reload, command/telemetry reload, or suite analysis causes the overlay content to be executed with the privileges of the COSMOS microservices, which include access to internal credentials and data. Because of the low complexity and high impact, this vulnerability poses an imminent threat to any COSMOS installation that is still using a vulnerable version.
OpenCVE Enrichment
Github GHSA