CVE-2025-28382: Path Traversal
An issue in the openc3-api/tables endpoint of OpenC3 COSMOS 6.0.0 allows attackers to execute a directory traversal.
Other sources
An issue in the openc3-api/tables endpoint of OpenC3 COSMOS before 6.1.0 allows attackers to execute a directory traversal.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-28382?
CVE-2025-28382 has been classified with a moderate severity level due to its potential for exploitation via directory traversal.
How do I fix CVE-2025-28382?
To fix CVE-2025-28382, update OpenC3 COSMOS to a patched version that removes the vulnerability in the tables endpoint.
What kind of attacks can be executed using CVE-2025-28382?
CVE-2025-28382 allows attackers to perform directory traversal attacks, potentially exposing sensitive files on the server.
Which versions of OpenC3 COSMOS are affected by CVE-2025-28382?
OpenC3 COSMOS version 6.0.0, both enterprise and open source, are affected by CVE-2025-28382.
Is there a workaround for CVE-2025-28382 until I can update?
A recommended workaround for CVE-2025-28382 is to restrict access to the openc3-api/tables endpoint until an update can be applied.