CVE-2026-77601: 
Ruby Analyse et atténuation des vulnérabilités

Aperçu

CVE-2026-77601 is an authenticated OS command injection vulnerability in OpenC3 COSMOS, a command and telemetry system for embedded systems. An authenticated actor can write a malicious value to the pypi_url setting via the JSON-RPC endpoint POST /openc3-api/api, which is then interpolated unescaped into a shell command executed via Ruby backtick during plugin installation with Python dependencies. The vulnerability affects OpenC3 COSMOS versions 5.12.0 through 7.2.1 (inclusive), and is fixed in version 7.3.0. It carries a CVSS v3.1 base score of 8.8 (High) (Github Advisory, OpenC3 Advisory).

Détails techniques

The root cause is CWE-78 (Improper Neutralization of Special Elements used in an OS Command). In openc3/lib/openc3/models/plugin_model.rb at line 288, PluginModel.install_phase2 reads the user-writable pypi_url setting via get_setting, appends /simple, and interpolates the result directly into a shell command string executed via Ruby backtick syntax (`/openc3/bin/pipinstall #{pip_args}`), which invokes /bin/sh -c. An attacker can inject shell metacharacters such as ; (command separator) and # (comment) — for example, https://pypi.org ; id > /tmp/A1_PWNED 2>&1 ; # — to execute arbitrary commands. The injection is triggered whenever the installed plugin gem contains a requirements.txt or pyproject.toml, both of which the attacker controls by supplying the plugin gem. In the open-source edition, the authorize function only validates the session token without enforcing permissions, so any authenticated user can reach the vulnerable code path; the Enterprise edition requires the admin role (OpenC3 Advisory, Fix PR).

Impact

Successful exploitation results in arbitrary OS command execution as the openc3 service user (uid 1001) inside the openc3-cosmos-cmd-tlm-api container, achieving full confidentiality, integrity, and availability compromise. The service process holds Redis/Valkey credentials and bucket (S3) credentials and operates across all scopes, meaning an attacker can exfiltrate stored telemetry and commanding data, steal infrastructure credentials, and tamper with any scope's data. In open-source deployments, the attack surface is any authenticated user; in Enterprise deployments, the prerequisite admin role already has plugin-driven code execution by design, so the practical new risk is that a configuration value becomes an unintended shell execution pathway (OpenC3 Advisory).

Exploitabilité

A proof-of-concept exploit with a complete, step-by-step HTTP attack sequence is publicly available in the GitHub Security Advisory, confirmed end-to-end against a live OpenC3 COSMOS deployment (OpenC3 Advisory). As of the advisory publication date, there is no evidence of in-the-wild exploitation. The EPSS score is approximately 0.581% (46th percentile), indicating a moderate near-term exploitation probability (Github Advisory). The vulnerability is not currently listed in the CISA Known Exploited Vulnerabilities catalog. No threat actor attribution has been reported; the vulnerability was discovered by researcher Marnick39 (OpenC3 Advisory).

Étapes d’exploitation

  1. Obtain a valid session token: Send a POST request to /openc3-api/auth/verify with valid credentials: {"password":"<password>"}. Save the returned session token for subsequent authenticated requests.

  2. Inject malicious pypi_url via JSON-RPC: POST to /openc3-api/api with the set_setting method, setting pypi_url to a value containing shell metacharacters:

POST /openc3-api/api
{"jsonrpc":"2.0","method":"set_setting",
 "params":["pypi_url","https://pypi.org ; id > /tmp/A1_PWNED 2>&1 ; #"],
 "keyword_params":{"scope":"DEFAULT"},"id":1}

The trailing # comments out the /simple suffix appended by the server and any remaining pip arguments.

  1. Craft and upload a malicious plugin gem: Create a Ruby gem containing a requirements.txt file (content can be minimal or empty). Upload it via multipart POST:
POST /openc3-api/plugins
(multipart: plugin=@malicious.gem, scope=DEFAULT)

Save the plugin_hash returned in the response.

  1. Trigger plugin installation: POST to /openc3-api/plugins/install/<id> with the plugin_hash from step 3 and scope=DEFAULT. This triggers PluginModel.install_phase2, which reads the poisoned pypi_url setting and executes it via Ruby backtick.

  2. Shell metacharacters execute arbitrary commands: The Ruby backtick passes the interpolated string to /bin/sh -c, interpreting ; as a command separator. The injected command (e.g., id) runs as the openc3 service user (uid 1001), with output redirected to /tmp/A1_PWNED. An attacker can substitute any payload — reverse shell, credential harvesting, data exfiltration — in place of the PoC command (OpenC3 Advisory).

Indicateurs de compromis

  • Network: Unexpected POST requests to /openc3-api/api with set_setting method and pypi_url parameter containing shell metacharacters (;, #, |, &); POST requests to /openc3-api/plugins uploading plugin gems from unusual sources; outbound connections from the openc3-cosmos-cmd-tlm-api container to unknown external hosts.
  • Logs: API access logs showing set_setting calls with pypi_url values containing characters outside a valid URL pattern; plugin installation log entries referencing unexpected pypi_url values; Logger.warn entries for Python package installation failures following a suspicious install.
  • File System: Unexpected files created in /tmp/ (e.g., /tmp/A1_PWNED or similar marker files); new scripts, binaries, or cron jobs created by the openc3 user (uid 1001) inside the container; unauthorized modifications to plugin gem files.
  • Process: Unusual child processes spawned by the puma or Ruby process (e.g., /bin/sh, bash, curl, wget, python, nc) during plugin installation; unexpected network connections initiated by the openc3 service user (OpenC3 Advisory).

Atténuation et solutions de contournement

Upgrade OpenC3 COSMOS to version 7.3.0, which resolves the vulnerability by replacing the Ruby backtick shell invocation with Open3.capture2e using an argv array (no shell interpolation) and adding a PypiUrl.validate utility that rejects any value that is not a valid http(s) URL, falling back to the default https://pypi.org/simple (Fix PR, Fix Commit). For deployments that cannot immediately upgrade, consider restricting network access to the /openc3-api/api and /openc3-api/plugins endpoints to trusted users only, and auditing the current pypi_url setting value for any injected content. In Enterprise deployments, limiting the admin role to the minimum necessary users reduces the attack surface (Github Advisory).

Réactions de la communauté

The vulnerability was discovered by researcher Marnick39 and responsibly disclosed to the OpenC3 project. The fix was developed by OpenC3 maintainer jmthomas and merged on June 29, 2026, with the security advisory published on September 23, 2026 (OpenC3 Advisory). No significant broader media coverage or notable community commentary beyond the official advisory has been identified at this time.

Ressources additionnelles

  • OpenC3 Advisory — Official security advisory with full PoC details
  • Github Advisory — GitHub Advisory Database entry (GHSA-vp3w-52v9-q57f)
  • Fix PR — Pull request implementing the fix
  • Fix Commit — Commit with code changes resolving the injection
  • v7.2.1 Release — Release notes referencing the security fix

Source: Ce rapport a été généré à l’aide de l’IA

Apparenté Ruby Vulnérabilités:

Identifiant CVE

Sévérité

Score

Technologies

Nom du composant

Exploit CISA KEV

A corrigé

Date de publication

CVE-2026-55107CRITICAL10
  • Ruby logoRuby
  • kobako
NonOuiSep 30, 2026
CVE-2026-77602CRITICAL9.9
  • Ruby logoRuby
  • openc3
NonOuiSep 23, 2026
CVE-2026-77601HIGH8.8
  • Ruby logoRuby
  • openc3
NonOuiSep 23, 2026
CVE-2026-84782HIGH8.2
  • Ruby logoRuby
  • rpm-sequoia-devel
NonOuiSep 29, 2026
GHSA-4825-p4xm-pcf2HIGH7.1
  • Ruby logoRuby
  • spree_api
NonOuiSep 22, 2026

Évaluation gratuite des vulnérabilités

Évaluez votre posture de sécurité dans le cloud

Évaluez vos pratiques de sécurité cloud dans 9 domaines de sécurité pour évaluer votre niveau de risque et identifier les failles dans vos défenses.

Demander une évaluation

Obtenez une démo personnalisée

Prêt(e) à voir Wiz en action ?

"La meilleure expérience utilisateur que j’ai jamais vue, offre une visibilité totale sur les workloads cloud."
David EstlickRSSI
"Wiz fournit une interface unique pour voir ce qui se passe dans nos environnements cloud."
Adam FletcherChef du service de sécurité
"Nous savons que si Wiz identifie quelque chose comme critique, c’est qu’il l’est réellement."
Greg PoniatowskiResponsable de la gestion des menaces et des vulnérabilités