---
id: CVE-2026-55748
title: >-
  OpenStack Horizon before 25.7.4 produces scripts for OpenStack RC file
  downloading that may have a crafted project name with shell metacharacters
summary: >-
  OpenStack Horizon before 25.7.4 produces scripts for OpenStack RC file
  downloading that may have a crafted project name with shell metacharacters.
  NOTE: some parties consider this a security hardening opportunity to address
  certain types…
severity: medium
cvss: 6
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:L'
cwe:
  - CWE-78
vendor: openstack
product: horizon
affected:
  - 'horizon >= 8.0.0, < 25.3.3'
  - 'horizon >= 25.4.0, < 25.5.3'
  - 'horizon >= 25.6.0, < 25.7.4'
patched:
  - horizon 25.7.4
published: '2026-06-17'
updated: '2026-09-22'
sourceUpdated: '2026-09-22T15:41:27.873'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-55748'
references:
  - url: 'https://launchpad.net/bugs/2152240'
    label: cve@mitre.org
  - url: 'https://wiki.openstack.org/wiki/OSSN/OSSN-0097'
    label: cve@mitre.org
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-55748'
  - url: 'https://github.com/openstack/horizon'
  - url: 'https://github.com/advisories/GHSA-6wrm-x65g-hr4p'
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-55748.json
  - url: 'https://access.redhat.com/security/cve/CVE-2026-55748'
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2489863'
  - url: 'https://www.cve.org/CVERecord?id=CVE-2026-55748'
tags:
  - nvd
  - osv
  - pip
  - ghsa
  - csaf
  - vex
  - red-hat
epss: 0.0046
epssPercentile: 0.37097
aliases:
  - GHSA-6wrm-x65g-hr4p
  - PYSEC-2026-2519
ecosystem: pip
ingestedAt: '2026-06-29T14:31:47.205Z'
---

## Overview

OpenStack Horizon before 25.7.4 produces scripts for OpenStack RC file downloading that may have a crafted project name with shell metacharacters. NOTE: some parties consider this a security hardening opportunity to address certain types of user error, not a vulnerability.

## Affected

- `horizon >= 8.0.0, < 25.3.3`
- `horizon >= 25.4.0, < 25.5.3`
- `horizon >= 25.6.0, < 25.7.4`

## Remediation

Upgrade past the affected range:

- `horizon 25.7.4`

## Package advisory (CVE-2026-55748)

Affected packages:

- `horizon <= 25.7.3`

Source: https://osv.dev/vulnerability/GHSA-6wrm-x65g-hr4p

## Vendor advisories

- **Red Hat VEX** · Moderate · affected: Red Hat OpenStack Platform 13 (Queens), Red Hat OpenStack Platform 16.2, Red Hat OpenStack Platform 17.1, Red Hat OpenStack Platform 18.0 · no fix planned: Red Hat OpenStack Platform 13 (Queens), Red Hat OpenStack Platform 16.2, Red Hat OpenStack Platform 17.1, Red Hat OpenStack Platform 18.0 · updated 2026-09-22 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-55748.json)
