GHSA-8xwf-cr4r-856r

Suggest an improvement
Source
https://github.com/advisories/GHSA-8xwf-cr4r-856r
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/02/GHSA-8xwf-cr4r-856r/GHSA-8xwf-cr4r-856r.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-8xwf-cr4r-856r
Aliases
Published
2026-02-27T06:31:28Z
Modified
2026-06-29T12:26:05Z
Severity
  • 9.1 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H CVSS Calculator
Summary
OpenStack Vitrage: Unauthorized Access to the Host can Lead to Eval Injection
Details

In the query parser in OpenStack Vitrage before 12.0.1, 13.0.0, 14.0.0, and 15.0.0, a user allowed to access the Vitrage API may trigger code execution on the Vitrage service host as the user the Vitrage service runs under. This may result in unauthorized access to the host and further compromise of the Vitrage service. All deployments exposing the Vitrage API are affected. This occurs in _create_query_function in vitrage/graph/query.py.

Database specific
{
    "cwe_ids":  [
        "CWE-95"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2026-02-28T02:24:32Z",
    "nvd_published_at":  "2026-02-27T05:18:20Z",
    "severity":  "CRITICAL"
}
References

Affected packages

PyPI / vitrage

Package

Affected ranges

Type
ECOSYSTEM
Events
Introduced
15.0.0.0rc1
Fixed
15.0.1

Affected versions

15.*
15.0.0.0rc1
15.0.0

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/02/GHSA-8xwf-cr4r-856r/GHSA-8xwf-cr4r-856r.json"

PyPI / vitrage

Package

Affected ranges

Type
ECOSYSTEM
Events
Introduced
14.0.0.0rc1
Fixed
14.0.1

Affected versions

14.*
14.0.0.0rc1
14.0.0

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/02/GHSA-8xwf-cr4r-856r/GHSA-8xwf-cr4r-856r.json"

PyPI / vitrage

Package

Affected ranges

Type
ECOSYSTEM
Events
Introduced
13.0.0.0rc1
Fixed
13.0.1

Affected versions

13.*
13.0.0.0rc1
13.0.0

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/02/GHSA-8xwf-cr4r-856r/GHSA-8xwf-cr4r-856r.json"

PyPI / vitrage

Package

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
12.0.1

Affected versions

0.*
0.0.1.dev451
0.2.0
0.7.0
1.*
1.0.0
1.1.0
1.2.0
1.3.0
1.4.0
1.5.0
1.5.1
1.5.2
1.6.0
1.7.0
1.8.0
1.8.1
1.8.2
1.8.3
2.*
2.0.0
2.1.0
2.2.0
2.3.0
3.*
3.0.0
3.1.0
3.2.0
3.3.0
4.*
4.0.0
4.1.0
4.2.0
4.3.0
4.3.1
4.3.2
5.*
5.0.0
5.0.1
5.0.2
6.*
6.0.0
6.0.1
7.*
7.0.0
7.1.0
7.2.0
7.3.0
7.4.0
7.5.0
8.*
8.0.0
8.0.1
9.*
9.0.0
10.*
10.0.0.0rc1
10.0.0
11.*
11.0.0.0rc1
11.0.0
12.*
12.0.0.0rc1
12.0.0.0rc2
12.0.0

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/02/GHSA-8xwf-cr4r-856r/GHSA-8xwf-cr4r-856r.json"