VulnSea

Mistral vulnerabilities

CVEs whose affected-version data names the Mistral package (pip). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

5 CVEsRSS

CVE-2026-93858High· 8.7PoC
yesterday

In OpenStack Mistral through 23.0.0, the std.ssh_proxied action passes a caller-supplied proxy_command value directly to paramiko.ProxyCommand() before any SSH connection to a gateway or target host is attempted

In OpenStack Mistral through 23.0.0, the std.ssh_proxied action passes a caller-supplied proxy_command value directly to paramiko.ProxyCommand() before any SSH connection to a gateway or target host is attempted. An authenticated project…

▾ MidnightOpenStack · Mistralvia NVD
CVE-2026-97147High· 7.2
yesterday

In OpenStack Mistral through 23.0.0, several of the v2 API write paths resolve the target object with a query that can return another project's resource, then write to it

In OpenStack Mistral through 23.0.0, several of the v2 API write paths resolve the target object with a query that can return another project's resource, then write to it. An authenticated project member can use this to rewrite and un-pu…

▾ TwilightOpenStack · Mistralvia NVD
CVE-2026-93860High· 7.1
yesterday

In OpenStack Mistral through 23.0.0, the /v2/maintenance API controller clears the request context and calls the maintenance service directly without any policy enforcement

In OpenStack Mistral through 23.0.0, the /v2/maintenance API controller clears the request context and calls the maintenance service directly without any policy enforcement. Any holder of a valid Mistral token, regardless of assigned rol…

▾ TwilightOpenStack · Mistralvia NVD
CVE-2026-93861Medium· 6.0
yesterday

In OpenStack Mistral through 23.0.0, the workflow membership API lets a project that has accepted a share of another project's private workflow create a further membership naming a third project

In OpenStack Mistral through 23.0.0, the workflow membership API lets a project that has accepted a share of another project's private workflow create a further membership naming a third project. The new membership row is created with it…

▾ SunlitOpenStack · Mistralvia NVD
CVE-2026-41283Critical· 9.9
4mo ago

OpenStack Mistral allows Arbitrary Remote Code Execution when the API is exposed

OpenStack Mistral allows Arbitrary Remote Code Execution when the API is exposed

▾ Midnightmistral · mistralEPSS 0.92%via OSV
Mistral vulnerabilities (CVEs) · VulnSea