Miggo Logo

CVE-2025-28384: OpenC3 COSMOS Vulnerable to Directory Traversal via /script-api/scripts/ endpoint

9.1

CVSS Score
3.1

Basic Information

EPSS Score
0.7782%
Published
6/13/2025
Updated
6/16/2025
KEV Status
No
Technology
TechnologyRuby

Technical Details

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Package NameEcosystemVulnerable VersionsFirst Patched Version
openc3-cosmos-tool-iframerubygems= 6.0.0

Vulnerability Intelligence
Miggo AIMiggo AI

Miggo AIRoot Cause Analysis:
In progress

WAF Protection Rules

WAF Rule

*n issu* in t** /s*ript-*pi/s*ripts/ *n*point o* Op*n** *OSMOS *.*.* *llows *tt**k*rs to *x**ut* * *ir**tory tr*v*rs*l.

Reasoning

No *n*lysis *v*il**l*