---
id: CVE-2021-4472
aliases:
  - GHSA-75hx-6r6j-hw56
  - PYSEC-2026-1849
title: OpenStack's Mistral Client has a local file inclusion vulnerability
summary: OpenStack's Mistral Client has a local file inclusion vulnerability
severity: medium
cvss: 6.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'
vendor: python-mistralclient
product: python-mistralclient
ecosystem: pip
affected:
  - python-mistralclient < 4.3.0
patched:
  - python-mistralclient 4.3.0
published: '2025-11-26'
updated: '2026-07-07'
source: OSV
sourceUrl: 'https://osv.dev/vulnerability/GHSA-75hx-6r6j-hw56'
references:
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2021-4472'
  - url: 'https://access.redhat.com/security/cve/CVE-2021-4472'
  - url: 'https://bugs.launchpad.net/horizon/+bug/1931558'
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2417321'
  - url: 'https://lists.debian.org/debian-lts-announce/2025/12/msg00002.html'
  - url: 'https://lists.debian.org/debian-lts-announce/2025/12/msg00003.html'
  - url: 'https://opendev.org/openstack/mistral-dashboard'
  - url: 'https://review.opendev.org/c/openstack/mistral-dashboard/+/800952'
  - url: 'https://review.opendev.org/c/openstack/python-mistralclient/+/800950'
tags:
  - osv
  - pip
epss: 0.00461
epssPercentile: 0.3926
ingestedAt: '2026-07-08T18:25:46.771Z'
---

## Overview

The mistral-dashboard plugin for openstack has a local file inclusion vulnerability through the 'Create Workbook' feature that may result in disclosure of arbitrary local files content.

## Affected packages

- `python-mistralclient < 4.3.0`

## Remediation

Upgrade to a patched release:

- `python-mistralclient 4.3.0`
