---
id: CVE-2024-28717
aliases:
  - GHSA-rfm2-f94j-qhjp
  - PYSEC-2026-1945
title: OpenStack Storlets arbitrary code execution vulnerability
summary: OpenStack Storlets arbitrary code execution vulnerability
severity: high
cvss: 7.8
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'
vendor: storlets
product: storlets
ecosystem: pip
affected:
  - storlets < 13.0.0.0rc1
patched:
  - storlets 13.0.0.0rc1
published: '2024-04-22'
updated: '2026-07-07'
source: OSV
sourceUrl: 'https://osv.dev/vulnerability/GHSA-rfm2-f94j-qhjp'
references:
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2024-28717'
  - url: >-
      https://github.com/openstack/storlets/commit/5ad58804af885db3eb7a78bea5000c401eeeb70e
  - url: 'https://bugs.launchpad.net/storlets/+bug/2047723'
  - url: 'https://gist.github.com/Fewword/f098d8d6375ac25e27b18c0e57be532f'
  - url: 'https://github.com/openstack/storlets'
tags:
  - osv
  - pip
epss: 0.00892
epssPercentile: 0.57747
ingestedAt: '2026-07-08T18:25:52.706Z'
---

## Overview

An issue in OpenStack Storlets yoga-eom allows a remote attacker to execute arbitrary code via the gateway.py component.

## Affected packages

- `storlets < 13.0.0.0rc1`

## Remediation

Upgrade to a patched release:

- `storlets 13.0.0.0rc1`
