CVE-2025-68271 is a critical remote code execution vulnerability affecting OpenC3 COSMOS versions 5.0.0 through 6.10.1. An unauthenticated attacker can exploit this flaw via the JSON-RPC API by manipulating string parameters, leading to Ruby code execution due to improper parsing and evaluation of array-like inputs. This vulnerability carries a CVSS score of 10.0 (Critical) with a network attack vector and no user interaction required, allowing for complete compromise of confidentiality, integrity, and availability. While there is no evidence of active exploitation, public exploit code, or Metasploit/Nuclei modules, the vulnerability has garnered some community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| OpenC3 | Cosmos | >= 5.0.0, < 6.10.2CNA affected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.