GHSA-p67j-387g-75wc
GitHub Security Advisory
OpenC3 COSMOS Vulnerable to Directory Traversal via /script-api/scripts/ endpoint
✓ GitHub Reviewed
CRITICAL
Has CVE
Advisory Details
An issue in the /script-api/scripts/ endpoint of OpenC3 COSMOS 6.0.0 allows attackers to execute a directory traversal.
Affected Packages
RubyGems
openc3-cosmos-tool-iframe
Related CVEs
Key Information
9.0
/10
Dataset
Last updated: June 18, 2025 6:25 AM
Data from GitHub Advisory Database. This information is provided for research and educational purposes.