CVE-2025-28381: High severity OpenC3 COSMOS vulnerability
Published Jun 13, 2025
·Updated
A credential leak in OpenC3 COSMOS before v6.0.2 allows attackers to access service credentials as environment variables stored in all containers.
Affected Software
2 affected components
OpenC3 COSMOS=6.0.0
OpenC3 COSMOS=6.0.0
Event History
Jun 13, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·02:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-28381?
CVE-2025-28381 is considered a critical vulnerability due to its potential to expose sensitive service credentials.
2
How do I fix CVE-2025-28381?
To fix CVE-2025-28381, it is recommended to upgrade OpenC3 COSMOS to a patched version that eliminates credential leakage.
3
What kind of data is exposed in CVE-2025-28381?
CVE-2025-28381 exposes service credentials stored as environment variables in all containers.
4
Which versions of OpenC3 COSMOS are affected by CVE-2025-28381?
The only affected version of OpenC3 COSMOS is v6.0.0.
5
Who is vulnerable to CVE-2025-28381?
Any organization that uses OpenC3 COSMOS v6.0.0 is vulnerable to CVE-2025-28381.