PYSEC-2026-564

See a problem?
Import Source
https://github.com/pypa/advisory-database/blob/main/vulns/vitrage/PYSEC-2026-564.yaml
JSON Data
https://api.osv.dev/v1/vulns/PYSEC-2026-564
Aliases
Published
2026-06-29T11:50:51Z
Modified
2026-07-02T13:00:06Z
Severity
  • 9.1 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H CVSS Calculator
Summary
OpenStack Vitrage: Unauthorized Access to the Host can Lead to Eval Injection
Details

In the query parser in OpenStack Vitrage before 12.0.1, 13.0.0, 14.0.0, and 15.0.0, a user allowed to access the Vitrage API may trigger code execution on the Vitrage service host as the user the Vitrage service runs under. This may result in unauthorized access to the host and further compromise of the Vitrage service. All deployments exposing the Vitrage API are affected. This occurs in _create_query_function in vitrage/graph/query.py.

References

Affected packages

PyPI / vitrage

Package

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
12.0.1
Introduced
13.0.0.0rc1
Fixed
13.0.1
Introduced
14.0.0.0rc1
Fixed
14.0.1
Introduced
15.0.0.0rc1
Fixed
15.0.1

Affected versions

0.*
0.0.1.dev451
0.2.0
0.7.0
1.*
1.0.0
1.1.0
1.2.0
1.3.0
1.4.0
1.5.0
1.5.1
1.5.2
1.6.0
1.7.0
1.8.0
1.8.1
1.8.2
1.8.3
2.*
2.0.0
2.1.0
2.2.0
2.3.0
3.*
3.0.0
3.1.0
3.2.0
3.3.0
4.*
4.0.0
4.1.0
4.2.0
4.3.0
4.3.1
4.3.2
5.*
5.0.0
5.0.1
5.0.2
6.*
6.0.0
6.0.1
7.*
7.0.0
7.1.0
7.2.0
7.3.0
7.4.0
7.5.0
8.*
8.0.0
8.0.1
9.*
9.0.0
10.*
10.0.0.0rc1
10.0.0
11.*
11.0.0.0rc1
11.0.0
12.*
12.0.0.0rc1
12.0.0.0rc2
12.0.0
13.*
13.0.0.0rc1
13.0.0
14.*
14.0.0.0rc1
14.0.0
15.*
15.0.0.0rc1
15.0.0

Database specific

source
"https://github.com/pypa/advisory-database/blob/main/vulns/vitrage/PYSEC-2026-564.yaml"