CVE-2025-28384: Path Traversal
An issue in the /script-api/scripts/ endpoint of OpenC3 COSMOS 6.0.0 allows attackers to execute a directory traversal.
Other sources
An issue in the /script-api/scripts/ endpoint of OpenC3 COSMOS before 6.1.0 allows attackers to execute a directory traversal.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-28384?
CVE-2025-28384 is rated as a critical vulnerability due to its potential for directory traversal attacks.
How do I fix CVE-2025-28384?
To remediate CVE-2025-28384, update OpenC3 COSMOS to the latest version where this vulnerability has been patched.
What systems are affected by CVE-2025-28384?
CVE-2025-28384 affects OpenC3 COSMOS version 6.0.0 in both enterprise and open source distributions.
What can attackers do with CVE-2025-28384?
Attackers exploiting CVE-2025-28384 can execute directory traversal attacks, potentially accessing sensitive files on the server.
When was CVE-2025-28384 disclosed?
CVE-2025-28384 was disclosed in 2025, highlighting a significant security flaw in OpenC3 COSMOS.