GHSA-9hfw-w3f4-c4p8CriticalCVSS 9.9
OpenStack Mistral allows Arbitrary Remote Code Execution when the API is exposed
🔗 CVE IDs covered (1)
📋 Description
OpenStack Mistral through 22.0.0 allows Arbitrary Remote Code Execution when the API is exposed. There are endpoints that allow code execution, which can lead to exfiltration of service credentials.
🎯 Affected products3
- pip/mistral:>= 20.0.0, < 20.1.1
- pip/mistral:= 21.0.0
- pip/mistral:= 22.0.0
🔗 References (9)
- https://nvd.nist.gov/vuln/detail/CVE-2026-41283
- https://github.com/openstack/mistral/tags
- https://www.openwall.com/lists/oss-security/2026/06/03/14
- http://www.openwall.com/lists/oss-security/2026/06/03/14
- https://security.openstack.org/ossa/OSSA-2026-020.html
- https://access.redhat.com/security/cve/CVE-2026-41283
- https://bugzilla.redhat.com/show_bug.cgi?id=2484607
- https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-41283.json
- https://github.com/advisories/GHSA-9hfw-w3f4-c4p8