GHSA-9hfw-w3f4-c4p8CriticalCVSS 9.9

OpenStack Mistral allows Arbitrary Remote Code Execution when the API is exposed

Published
June 4, 2026
Last Modified
July 14, 2026

🔗 CVE IDs covered (1)

📋 Description

OpenStack Mistral through 22.0.0 allows Arbitrary Remote Code Execution when the API is exposed. There are endpoints that allow code execution, which can lead to exfiltration of service credentials.

🎯 Affected products3

  • pip/mistral:>= 20.0.0, < 20.1.1
  • pip/mistral:= 21.0.0
  • pip/mistral:= 22.0.0

🔗 References (9)