CVE-2026-42086
Last modified
CVE-2026-42086 is a medium-severity vulnerability rated 4.6/10 on the CVSS scale. OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. Prior to version 7.0.0, the Command Sender UI uses an unsafe eval() function on array-like command parameters, which allows a user-supplied payload to execute in the browser when sending a command. EPSS estimates a 0.20% chance of exploitation in the next 30 days.
Description
OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. Prior to version 7.0.0, the Command Sender UI uses an unsafe eval() function on array-like command parameters, which allows a user-supplied payload to execute in the browser when sending a command. This creates a self-XSS risk because an attacker can trigger their own script execution in the victim’s session, if allowed to influence the array parameter input, for example via phishing. If successful, an attacker may read or modify data in the authenticated browser context, including session tokens in local storage. This issue has been patched in version 7.0.0.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions | Update |
|---|---|---|---|
| Openc3 | Cosmos | < 7.0.0 | — |
| Openc3 | Cosmos | 7.0.0 | Rc1 |
References
- https://github.com/OpenC3/cosmos/security/advisories/GHSA-ffq5-qpvf-xq7xExploit, Vendor Advisory
- https://github.com/OpenC3/cosmos/security/advisories/GHSA-ffq5-qpvf-xq7xExploit, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2026-42086?
How severe is CVE-2026-42086?
How do I fix CVE-2026-42086?
Are you affected by CVE-2026-42086?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
