CVE-2026-55748 - OpenStack Horizon: Arbitrary Command Injection via Crafted Project Name in RC File Download
CVE ID :CVE-2026-55748
Published : June 17, 2026, 2:12 p.m. | 1 hour, 26 minutes ago
Description :OpenStack Horizon before 25.7.4 produces scripts for OpenStack RC file downloading that may have a crafted project name with shell metacharacters. NOTE: some parties consider this a security hardening opportunity to address certain types of user error, not a vulnerability.
Severity: 6.0 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Published : June 17, 2026, 2:12 p.m. | 1 hour, 26 minutes ago
Description :OpenStack Horizon before 25.7.4 produces scripts for OpenStack RC file downloading that may have a crafted project name with shell metacharacters. NOTE: some parties consider this a security hardening opportunity to address certain types of user error, not a vulnerability.
Severity: 6.0 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...