Skip to main content

Security Vulnerabilities

Below is a list of CVEs reported in COSMOS. This does not include CVEs in our dependencies - you can find those in our Trivy scans.

Publishing CVEs

Due to the recent rise in submitted CVEs, Github has fallen behind in issuing and publishing CVEs. Thus some of these URLs may not yet resolve in the database even though they have been assigned.

Patched​

CVEPatched VersionAffected EditionsDescription
CVE-2024-437955.19.0Core onlyXSS exploit in login screen
CVE-2024-469775.19.0Core & EnterprisePath traversal for .txt files via LocalMode's open_local_file function
CVE-2024-475295.19.0Core onlyPlaintext storage of password in browser LocalStorage
CVE-2025-283806.0.2Core & EnterpriseXSS exploit via crafted URLs to the Documentation Tool or via stored screens with the IFRAME widget in Telemetry Viewer
CVE-2025-283816.0.2Core & EnterpriseCertain Docker credentials were leaked through environment variables, readable by authenticated users in Script Runner
CVE-2025-283826.1.0Core & EnterpriseArbitrary file read/copy/delete via the Table Manager API
CVE-2025-283846.1.0Core & EnterpriseArbitrary file read via the Script Runner API
CVE-2025-283886.0.2Core onlyHardcoded credentials for the service account (used by running scripts to access the API - no admin permissions)
CVE-2025-682716.10.2Core & EnterpriseCritical remote code execution vulnerability reachable through the JSON-RPC API by an unauthenticated attacker
CVE-2026-420886.10.5 & 7.0.0Core & EnterpriseAdministrative Actions via the Script Runner Tool
CVE-2026-420856.10.5 & 7.0.0Core & EnterpriseArbitrary write to plugins directory via path-traversed config filenames
CVE-2026-420846.10.5 & 7.0.0Core & EnterpriseHijacked session token can be used to reset password for persistence
CVE-2026-420876.10.6 & 7.0.0Core & EnterpriseSQL Injection in QuestDB Time-Series Data Base
CVE-2026-420866.10.6 & 7.0.0Core & EnterpriseSelf-XSS in the Command Sender
CVE-2025-283897.0.0Core onlyAPI accepts plaintext passwords for authentication (will NOT be backported to COSMOS 6)
CVE-2026-776027.3.0Core & EnterpriseNon-admin users can write to targets_modified which is evaluated by ERB in various places and thus can execute arbitrary Ruby code
CVE-2026-776017.3.0Core & EnterpriseThe pypi_url setting is evaluated and can execute arbitrary host commands
CVE-2026-773947.3.0Core & EnterpriseBUTTON widgets in Telemetry Viewer can execute arbitrary javascript code
CVE-2026-921657.3.0Core & EnterpriseUnauthenticated network clients can logout authenticated users resulting in DOS
CVE-2026-921667.3.0Core & EnterpriseThe JsonDRb method whitelist doesn't include public_send and therefore can execute arbitrary methods
CVE-2026-921677.4.0Core & EnterpriseA variable length packet with deliberately malformed length field can cause a heap overflow DOS
CVE-2026-921687.4.0Core & EnterpriseAn authenticated remote user can break the COSMOS news feed
CVE-2026-921697.4.0Core & EnterpriseAn authenticated script runner role can execute arbitrary Ruby code via Script Suites

Open​

CVEAffected EditionsDescriptionWhy is it still open?
CVE-2025-28386Core & EnterpriseRCE via installing a pluginWon't fix: this is inherent to the functionality of plugins - if plugins couldn't execute code, you couldn't customize COSMOS. Only authenticated users can load code for execution, and in Enterprise that user must have admin permissions.