Security Vulnerabilities
Below is a list of CVEs reported in COSMOS. This does not include CVEs in our dependencies - you can find those in our Trivy scans.
Publishing CVEs
Due to the recent rise in submitted CVEs, Github has fallen behind in issuing and publishing CVEs. Thus some of these URLs may not yet resolve in the database even though they have been assigned.
Patched
| CVE | Patched Version | Affected Editions | Description |
|---|---|---|---|
| CVE-2024-43795 | 5.19.0 | Core only | XSS exploit in login screen |
| CVE-2024-46977 | 5.19.0 | Core & Enterprise | Path traversal for .txt files via LocalMode's open_local_file function |
| CVE-2024-47529 | 5.19.0 | Core only | Plaintext storage of password in browser LocalStorage |
| CVE-2025-28380 | 6.0.2 | Core & Enterprise | XSS exploit via crafted URLs to the Documentation Tool or via stored screens with the IFRAME widget in Telemetry Viewer |
| CVE-2025-28381 | 6.0.2 | Core & Enterprise | Certain Docker credentials were leaked through environment variables, readable by authenticated users in Script Runner |
| CVE-2025-28382 | 6.1.0 | Core & Enterprise | Arbitrary file read/copy/delete via the Table Manager API |
| CVE-2025-28384 | 6.1.0 | Core & Enterprise | Arbitrary file read via the Script Runner API |
| CVE-2025-28388 | 6.0.2 | Core only | Hardcoded credentials for the service account (used by running scripts to access the API - no admin permissions) |
| CVE-2025-68271 | 6.10.2 | Core & Enterprise | Critical remote code execution vulnerability reachable through the JSON-RPC API by an unauthenticated attacker |
| CVE-2026-42088 | 6.10.5 & 7.0.0 | Core & Enterprise | Administrative Actions via the Script Runner Tool |
| CVE-2026-42085 | 6.10.5 & 7.0.0 | Core & Enterprise | Arbitrary write to plugins directory via path-traversed config filenames |
| CVE-2026-42084 | 6.10.5 & 7.0.0 | Core & Enterprise | Hijacked session token can be used to reset password for persistence |
| CVE-2026-42087 | 6.10.6 & 7.0.0 | Core & Enterprise | SQL Injection in QuestDB Time-Series Data Base |
| CVE-2026-42086 | 6.10.6 & 7.0.0 | Core & Enterprise | Self-XSS in the Command Sender |
| CVE-2025-28389 | 7.0.0 | Core only | API accepts plaintext passwords for authentication (will NOT be backported to COSMOS 6) |
| CVE-2026-77602 | 7.3.0 | Core & Enterprise | Non-admin users can write to targets_modified which is evaluated by ERB in various places and thus can execute arbitrary Ruby code |
| CVE-2026-77601 | 7.3.0 | Core & Enterprise | The pypi_url setting is evaluated and can execute arbitrary host commands |
| CVE-2026-77394 | 7.3.0 | Core & Enterprise | BUTTON widgets in Telemetry Viewer can execute arbitrary javascript code |
| CVE-2026-92165 | 7.3.0 | Core & Enterprise | Unauthenticated network clients can logout authenticated users resulting in DOS |
| CVE-2026-92166 | 7.3.0 | Core & Enterprise | The JsonDRb method whitelist doesn't include public_send and therefore can execute arbitrary methods |
| CVE-2026-92167 | 7.4.0 | Core & Enterprise | A variable length packet with deliberately malformed length field can cause a heap overflow DOS |
| CVE-2026-92168 | 7.4.0 | Core & Enterprise | An authenticated remote user can break the COSMOS news feed |
| CVE-2026-92169 | 7.4.0 | Core & Enterprise | An authenticated script runner role can execute arbitrary Ruby code via Script Suites |
Open
| CVE | Affected Editions | Description | Why is it still open? |
|---|---|---|---|
| CVE-2025-28386 | Core & Enterprise | RCE via installing a plugin | Won't fix: this is inherent to the functionality of plugins - if plugins couldn't execute code, you couldn't customize COSMOS. Only authenticated users can load code for execution, and in Enterprise that user must have admin permissions. |