Openc3
This hub aggregates every CVE we track for Openc3, a product in the oss libraries space. Use it to gauge the current risk picture and drill into individual advisories.
9
CVEs tracked
1
Critical
0
High
0
In CISA KEV
Severity distribution
MEDIUM3CRITICAL1
Monthly trend
3
0
0
0
0
0
0
0
0
0
0
0
0
0
0
1
0
0
5
0
0
0
0
0
2024-102026-09
Latest CVEs
The 9 most recently published vulnerabilities affecting Openc3.
- GHSA-2wvh-87g2-89hrOpenC3 COSMOS: Permissions Bypass Provides User Access to Unassigned Administrative Actions via Script Runner Tool
- GHSA-v529-vhwc-wfc5OpenC3 COSMOS has SQL Injection in QuestDB Time-Series Database
- GHSA-ffq5-qpvf-xq7xOpenC3 COSMOS is Vulnerable to Self-XSS Through the Command Sender
- GHSA-4jvx-93h3-f45hOpenC3 COSMOS allows arbitrary writes to plugins directory via path-traversed config filenames
- GHSA-wgx6-g857-jjf7OpenC3 COSMOS: Hijacked session token can be used to reset password for persistence
- CVE-2025-68271Unauthenticated Remote Code Execution in openc3-api10.0
- CVE-2024-47529OpenC3 COSMOS uses clear text storage of password/token (`GHSL-2024-129`)6.5
- CVE-2024-46977OpenC3 COSMOS allows a path traversal via screen controller (`GHSL-2024-127`)6.5
- CVE-2024-43795OpenC3 COSMOS vulnerable to cross-site scripting in Login functionality (`GHSL-2024-128`)6.1
Product normalization is registry-driven with AI assist and human review. How it works