Skip to content

Commit cfad0cc

Browse files
jasnowRubySec CI
authored andcommitted
Updated advisory posts against rubysec/ruby-advisory-db@47b5bdc
1 parent 09f7b69 commit cfad0cc

2 files changed

Lines changed: 153 additions & 0 deletions

File tree

Lines changed: 57 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,57 @@
1+
---
2+
layout: advisory
3+
title: 'CVE-2026-77601 (openc3): OpenC3 COSMOS - Authenticated OS command injection
4+
via the `pypi_url` setting'
5+
comments: false
6+
categories:
7+
- openc3
8+
advisory:
9+
gem: openc3
10+
cve: 2026-77601
11+
ghsa: vp3w-52v9-q57f
12+
url: https://nvd.nist.gov/vuln/detail/CVE-2026-77601
13+
title: OpenC3 COSMOS - Authenticated OS command injection via the `pypi_url` setting
14+
date: 2026-07-11
15+
description: |-
16+
## Summary
17+
18+
An authenticated user can execute arbitrary operating system commands
19+
on the `openc3-cosmos-cmd-tlm-api` service. The `pypi_url` setting
20+
is interpolated, unescaped, into a command line that is run through
21+
a shell backtick when a plugin is installed. Shell metacharacters
22+
in the setting value are executed by `/bin/sh`.
23+
24+
## Impact
25+
26+
Arbitrary OS command execution as the `openc3` user (uid 1001) inside
27+
the cmd-tlm-api container. That process holds the Redis/Valkey password
28+
and the bucket (S3) credentials and operates across every scope, so
29+
command execution there exposes stored telemetry, commanding, and
30+
credentials, and allows tampering with any scope.
31+
32+
In the Enterprise edition the prerequisite is the admin role; the
33+
admin already has plugin-driven code execution by design, so the
34+
practical effect there is that a configuration value becomes a shell
35+
command rather than a new privilege boundary being crossed. In the
36+
open-source edition any authenticated user reaches it.
37+
cvss_v3: 8.8
38+
unaffected_versions:
39+
- "< 5.12.0"
40+
patched_versions:
41+
- ">= 7.2.1"
42+
related:
43+
url:
44+
- https://nvd.nist.gov/vuln/detail/CVE-2026-77601
45+
- https://rubygems.org/gems/openc3/versions/7.2.1
46+
- https://github.com/OpenC3/cosmos/releases/tag/v7.2.1
47+
- https://github.com/OpenC3/cosmos/pull/3489
48+
- https://github.com/OpenC3/cosmos/commit/be70d1d836c83c3b084e768e31a399312d4cbe0b
49+
- https://osv.dev/vulnerability/GHSA-vp3w-52v9-q57f
50+
- https://advisories.gitlab.com/gem/openc3/CVE-2026-77601
51+
- https://github.com/OpenC3/cosmos/security/advisories/GHSA-vp3w-52v9-q57f
52+
- https://github.com/advisories/GHSA-vp3w-52v9-q57f
53+
notes: |
54+
- cvss_v3 in GHSA and nvd.nist.gov URLs.
55+
- date from rubygems.org URL
56+
- Found PR#3489 in release 7.2.1 release notes so changed patched_versions.
57+
---
Lines changed: 96 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,96 @@
1+
---
2+
layout: advisory
3+
title: 'CVE-2026-77602 (openc3): OpenC3 COSMOS - Authenticated remote code execution
4+
via the user-writable config overlay (table definitions, cmd/tlm definitions, and
5+
script suites)'
6+
comments: false
7+
categories:
8+
- openc3
9+
advisory:
10+
gem: openc3
11+
cve: 2026-77602
12+
ghsa: jjq7-m736-w977
13+
url: https://nvd.nist.gov/vuln/detail/CVE-2026-77602
14+
title: OpenC3 COSMOS - Authenticated remote code execution via the user-writable
15+
config overlay (table definitions, cmd/tlm definitions, and script suites)
16+
date: 2026-07-11
17+
description: |-
18+
## Summary
19+
20+
COSMOS reads configuration from a user-writable overlay (`targets_modified/`)
21+
before the read-only plugin-installed `targets/` tree, and the config
22+
subsystem executes code on those files: `ConfigParser` renders every
23+
file as ERB by default, a `GENERIC_READ_CONVERSION` /
24+
`GENERIC_WRITE_CONVERSION` block is evaluated as code by
25+
`GenericConversion` (Ruby and Python), and the Script Runner suite
26+
analysis `require`s a procedure file. An authenticated user can write
27+
into `targets_modified/` below the admin tier (the storage-upload
28+
endpoint exempts that area from the admin gate, and the screen-save
29+
endpoint stores its body verbatim there), so the same root cause is
30+
reachable through several features, each giving arbitrary code
31+
execution on a COSMOS server.
32+
33+
Three vulnerable routes were identified, all reachable by an
34+
authenticated non-admin user (in the open-source edition `authorize`
35+
ignores the permission string, so any authenticated user qualifies):
36+
37+
1. **Table definitions** (immediate). `tables#generate|report|load`
38+
reads a definition from `targets_modified/` and ERB-renders it
39+
and evaluates its `GENERIC_*_CONVERSION` block in the
40+
`cmd-tlm-api` container.
41+
42+
2. **Command/telemetry definitions** (persistent). A file written
43+
to `targets_modified/<TARGET>/cmd_tlm/` is overlaid by
44+
`System.setup_targets` and processed by `PacketConfig` in the
45+
decom/multi microservices: ERB-rendered in the Ruby implementation,
46+
and GENERIC-evaluated in both the Ruby and Python implementations
47+
(the Python `ConfigParser` does not run ERB). It executes on
48+
the next microservice (re)start.
49+
50+
3. **Script Runner suites** (immediate). A procedure written to
51+
`targets_modified/<TARGET>/procedures/` is `require`d by the
52+
suite analysis, reachable at the read-only `script_view` tier
53+
through `scripts#body` and `running_script#show` (the analysis
54+
subprocess is spawned when `OPENC3_SERVICE_PASSWORD` is
55+
configured, which it is in the shipped `.env`).
56+
57+
### Impact
58+
59+
Arbitrary code execution as the `openc3` user in the `cmd-tlm-api`
60+
container and the per-target decom microservices and the script-runner.
61+
Those processes hold the Redis and bucket credentials and sit on the
62+
internal service network, so the executed code acts with that authority
63+
over configuration, telemetry, and command data across scopes. The
64+
API is served through Traefik, which the shipped compose binds to
65+
`127.0.0.1:2900`, so a default single-host install is reachable only
66+
from the host; a multi-user deployment exposes the web port, and the
67+
`AV:N` rating reflects that standard remote-operator exposure.
68+
69+
All paths require valid authentication, and the triggering permissions
70+
(`system`/`system_set`/`script_view`) are below the `admin`/`script_run`/
71+
lugin-install tiers where COSMOS gates code execution. In the
72+
open-source edition `authorize` checks only token validity and does
73+
not enforce the permission string, so any authenticated user can
74+
perform these requests.
75+
cvss_v3: 9.9
76+
unaffected_versions:
77+
- "< 5.1.0"
78+
patched_versions:
79+
- ">= 7.2.1"
80+
related:
81+
url:
82+
- https://nvd.nist.gov/vuln/detail/CVE-2026-77602
83+
- https://rubygems.org/gems/openc3/versions/7.2.1
84+
- https://github.com/OpenC3/cosmos/releases/tag/v7.2.1
85+
- https://github.com/OpenC3/cosmos/pull/3488
86+
- https://github.com/OpenC3/cosmos/commit/71943352a28128ef3e7e894319d97a656b5cd4f2
87+
- https://github.com/OpenC3/cosmos/commit/7a1538a4626f82c0d1540fcaa27ffdcbbd71ff81
88+
- https://advisories.gitlab.com/gem/openc3/CVE-2026-77602
89+
- https://osv.dev/vulnerability/GHSA-jjq7-m736-w977
90+
- https://github.com/OpenC3/cosmos/security/advisories/GHSA-jjq7-m736-w977
91+
- https://github.com/advisories/GHSA-jjq7-m736-w977
92+
notes: |
93+
- cvss_v3 in GHSA and nvd.nist.gov URLs.
94+
- date from rubygems.org URL
95+
- Found PR#3488 in release 7.2.1 release notes so changed patched_versions.
96+
---

0 commit comments

Comments
 (0)