Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-6wrm-x65g-hr4p | OpenStack Horizon RC file generation does not escape special characters in project names |
Fri, 19 Jun 2026 12:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 18 Jun 2026 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | OpenStack Horizon: OpenStack Horizon: Information disclosure or integrity compromise via crafted project name with shell metacharacters | |
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Thu, 18 Jun 2026 04:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | OpenStack Horizon before 25.7.4 produces scripts for OpenStack RC file downloading that may have a crafted project name with shell metacharacters. NOTE: some parties consider this a security hardening opportunity to address certain types of user error, not a vulnerability. | |
| First Time appeared |
Openstack
Openstack horizon |
|
| Weaknesses | CWE-78 | |
| CPEs | cpe:2.3:a:openstack:horizon:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Openstack
Openstack horizon |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-06-17T15:40:12.791Z
Reserved: 2026-06-17T14:12:20.286Z
Link: CVE-2026-55748
Updated: 2026-06-17T15:40:08.717Z
No data.
OpenCVE Enrichment
Updated: 2026-06-18T21:45:04Z
Github GHSA