CRITICAL9.8
PYSEC-2025-258
Details
OpenC3 COSMOS before v6.0.2 was discovered to contain hardcoded credentials for the Service Account.
Are you affected?
Enter the version of the package you're using.
Affected packages
PyPI/openc3
Introduced in:
0No fixed version published yet for openc3 (pip). Pin to a known-safe version or switch to an alternative.
References
- https://github.com/OpenC3/cosmos/pull/1816/commits/195974a019f375f7c5a35f48e4151babb40649ac[WEB]
- https://github.com/OpenC3/cosmos/releases/tag/v6.0.2[WEB]
- https://openc3.com/[WEB]
- https://github.com/OpenC3/cosmos/pull/1816[FIX]
- https://visionspace.com/openc3-cosmos-a-security-assessment-of-an-open-source-mission-framework/[EVIDENCE]