Skip to content

Commit bc76a85

Browse files
jasnowpostmodern
andauthored
GHSA SYNC: 2 brand new advisories (#878)
--------- Co-authored-by: Postmodern <postmodern.mod3@gmail.com>
1 parent 8b57546 commit bc76a85

File tree

2 files changed

+42
-0
lines changed

2 files changed

+42
-0
lines changed
Lines changed: 21 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,21 @@
1+
---
2+
gem: openc3-cosmos-tool-iframe
3+
cve: 2025-28382
4+
ghsa: cf8v-5mrc-jv7f
5+
url: https://github.com/advisories/GHSA-cf8v-5mrc-jv7f
6+
title: OpenC3 COSMOS Vulnerable to Directory Traversal via
7+
openc3-api/tables endpoint
8+
date: 2025-06-13
9+
description: |
10+
An issue in the openc3-api/tables endpoint of OpenC3 COSMOS
11+
6.0.0 allows attackers to execute a directory traversal.
12+
cvss_v3: 7.5
13+
unaffected_versions:
14+
- "< 6.0.0"
15+
notes: Never patched
16+
related:
17+
url:
18+
- https://nvd.nist.gov/vuln/detail/CVE-2025-28382
19+
- https://visionspace.com/openc3-cosmos-a-security-assessment-of-an-open-source-mission-framework
20+
- https://openc3.com
21+
- https://github.com/advisories/GHSA-cf8v-5mrc-jv7f
Lines changed: 21 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,21 @@
1+
---
2+
gem: openc3-cosmos-tool-iframe
3+
cve: 2025-28384
4+
ghsa: p67j-387g-75wc
5+
url: https://github.com/advisories/GHSA-p67j-387g-75wc
6+
title: OpenC3 COSMOS Vulnerable to Directory Traversal via
7+
/script-api/scripts/ endpoint
8+
date: 2025-06-13
9+
description: |
10+
An issue in the /script-api/scripts/ endpoint of OpenC3 COSMOS
11+
6.0.0 allows attackers to execute a directory traversal.
12+
cvss_v3: 9.1
13+
unaffected_versions:
14+
- "< 6.0.0"
15+
notes: Never patched
16+
related:
17+
url:
18+
- https://nvd.nist.gov/vuln/detail/CVE-2025-28384
19+
- https://visionspace.com/openc3-cosmos-a-security-assessment-of-an-open-source-mission-framework
20+
- https://openc3.com
21+
- https://github.com/advisories/GHSA-p67j-387g-75wc

0 commit comments

Comments
 (0)