GHSA-ffq5-qpvf-xq7x · Severity: medium · Ecosystem: rubygems — OpenC3 COSMOS is Vulnerable to Self-XSS Through the Command Sender
OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. Prior to version 7.0.0, the Command Sender UI uses an unsafe eval() function on array-like command parameters, which allows a user-supplied payload to execute in the browser when sending a command. This creates a self-XSS risk because an attacker can trigger their own script execution in the victim’s session, if allowed to influence the array parameter input, for example via phishing. If successful, an attacker may read or modify data in the authenticated browser context, including session tokens in local storage. This issue has been patched in version 7.0.0.
Conclusion & alert: CVE-2026-42086 is rated Exploit Available (50/100): CVSS Medium severity, with low exploitation likelihood (EPSS 0.20%). Core evidence: 1 public exploit reference(s) are indexed (Exploit-DB). Mandatory action: Public exploits are available—assess exposure, apply mitigations, and prioritize patching.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
| EDB-ID | Source | Kind | Published | Link |
|---|---|---|---|---|
| — | nvd_ref | exploit_tag | Exploit-DB ↗ |
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-06-15 | 0.03% | 0.20% | +0.17% |
| 2 | 2026-05-05 | — | 0.03% | — |
Full EPSS history (2 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 4.6 | 3.1 | MEDIUM |
|
2.1 | 2.5 | [email protected] |
GHSA-ffq5-qpvf-xq7x · Severity: medium · Ecosystem: rubygems — OpenC3 COSMOS is Vulnerable to Self-XSS Through the Command Sender
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| openc3 | cosmos | < 7.0.0 | cpe:2.3:a:openc3:cosmos:*:*:*:*:open_source:*:*:* |
| openc3 | cosmos | 7.0.0 | cpe:2.3:a:openc3:cosmos:7.0.0:rc1:*:*:open_source:*:*:* |
| openc3 | cosmos | 7.0.0 | cpe:2.3:a:openc3:cosmos:7.0.0:rc2:*:*:open_source:*:*:* |
| openc3 | cosmos | 7.0.0 | cpe:2.3:a:openc3:cosmos:7.0.0:rc3:*:*:open_source:*:*:* |
| URL | Tags |
|---|---|
| https://github.com/OpenC3/cosmos/security/advisories/GHSA-ffq5-qpvf-xq7x | Exploit Vendor Advisory |