VulnSea

openc3 has 9 CVEs on record between 2025 and 2026. The busiest recent month was May 2026 with 4. The median CVSS is 8.1 (high), with 3 rated critical. None have a confirmed exploitation report.

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
8.1
Publish → KEV
Last 90 days
0 prev 4

Products

  • openc3 9
9
Total CVEs
3
Critical
0
CISA KEV
0
Exploited

openc3 vulnerabilities

CVEs affecting openc3, newest first. Open any entry for full detail, references, and exploit status.

9 CVEsRSS

CVE-2026-42088High· 8.1
4mo ago

OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. Prior to version …

OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. Prior to version 7.0.0-rc3, the Script Runner widget allows users to execute Python and Ruby scripts directly from th…

Twilightopenc3 · openc3EPSS 0.34%via OSV
CVE-2026-42087Critical· 9.6
4mo ago

OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. From version 6.7.…

OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. From version 6.7.0 to before version 7.0.0-rc3, a SQL injection vulnerability exists in the Time-Series Database (TSD…

Midnightopenc3 · openc3EPSS 0.32%via OSV
CVE-2026-42085Medium· 4.3
4mo ago

OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. Prior to versions…

OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. Prior to versions 6.10.5 and 7.0.0-rc3, OpenC3 COSMOS contains a design flaw in the save_tool_config() function that …

Sunlitopenc3 · openc3EPSS 0.31%via OSV
CVE-2026-42084High· 8.1
4mo ago

OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. Prior to versions…

OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. Prior to versions 6.10.5 and 7.0.0-rc3, the OpenC3 password change functionality allows a user to change their passwo…

Twilightopenc3 · openc3EPSS 0.30%via OSV
CVE-2025-28388Critical· 9.8
1y ago

OpenC3 COSMOS before v6.0.2 was discovered to contain hardcoded credentials for the Service Account.

OpenC3 COSMOS before v6.0.2 was discovered to contain hardcoded credentials for the Service Account.

Midnightopenc3 · openc3EPSS 0.61%via OSV
CVE-2025-28384Critical· 9.1
1y ago

An issue in the /script-api/scripts/ endpoint of OpenC3 COSMOS before 6.1.0 allows attackers to execute a directory traversal.

An issue in the /script-api/scripts/ endpoint of OpenC3 COSMOS before 6.1.0 allows attackers to execute a directory traversal.

Midnightopenc3 · openc3EPSS 0.89%via OSV
CVE-2025-28382High· 7.5
1y ago

An issue in the openc3-api/tables endpoint of OpenC3 COSMOS before 6.1.0 allows attackers to execute a directory traversal.

An issue in the openc3-api/tables endpoint of OpenC3 COSMOS before 6.1.0 allows attackers to execute a directory traversal.

Twilightopenc3 · openc3EPSS 0.89%via OSV
CVE-2025-28381High· 7.5
1y ago

A credential leak in OpenC3 COSMOS before v6.0.2 allows attackers to access service credentials as environment variables stored in all co…

A credential leak in OpenC3 COSMOS before v6.0.2 allows attackers to access service credentials as environment variables stored in all containers.

Twilightopenc3 · openc3EPSS 0.52%via OSV
CVE-2025-28380Medium· 6.1
1y ago

A cross-site scripting (XSS) vulnerability in OpenC3 COSMOS before v6.0.2 allows attackers to execute arbitrary web scripts or HTML via i…

A cross-site scripting (XSS) vulnerability in OpenC3 COSMOS before v6.0.2 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the URL parameter.

Sunlitopenc3 · openc3EPSS 0.34%via OSV
openc3 vulnerabilities (CVEs) · VulnSea