openc3 is vulnerable to Code Injection
88
High Risk
Script Runner's suite mode builds a Ruby code string by interpolating the client supplied suite, group, and method values from a script run request and runs it with class_eval, without validating that the values are plain identifiers. A user who holds only the script_run permission - restricted to running pre-approved scripts, not editing them - can place arbitrary Ruby in the suite field and get it executed inside the Script Runner container, bypassing the script approval control that separates that role from script_edit. The fix validates suite, group, and method as identifiers before they reach run_text.
You are affected if you are using a version that falls within the vulnerable range and you rely on the script approval/lifecycle control to restrict a role with only script_run from executing unapproved code, such as in COSMOS Enterprise or another per target RBAC deployment.
openc3 is vulnerable to Code Injection in versions 6.5.0 - 7.3.0.
Upgrade the openc3 library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.