{
  "advisories": [
    {
      "id": "GHSA-6wrm-x65g-hr4p",
      "source": "ghsa",
      "title": "OpenStack Horizon RC file generation does not escape special characters in project names",
      "url": "https://github.com/advisories/GHSA-6wrm-x65g-hr4p"
    }
  ],
  "cve": "CVE-2026-55748",
  "enrichment": {
    "affected": [
      {
        "configurations": [
          {
            "platform": null,
            "status": "affected",
            "versions": {
              "scheme": "semver",
              "value": "[8.0.0,25.3.3)"
            }
          },
          {
            "platform": null,
            "status": "affected",
            "versions": {
              "scheme": "semver",
              "value": "[25.4.0,25.5.3)"
            }
          },
          {
            "platform": null,
            "status": "affected",
            "versions": {
              "scheme": "semver",
              "value": "[25.6.0,25.7.4)"
            }
          }
        ],
        "enrichment": {
          "confidence": 95.0,
          "confidence_source": "inferred",
          "scores": [
            {
              "score": 95.0,
              "source": "inferred"
            },
            {
              "score": 100.0,
              "source": "matching"
            }
          ]
        },
        "original": {
          "product": "Horizon",
          "source": "cna",
          "vendor": "OpenStack"
        },
        "product": "horizon",
        "vendor": "openstack"
      }
    ],
    "created": "2026-06-18T20:45:03.338786+00:00",
    "updated": "2026-06-18T21:45:04.768019+00:00",
    "vendors": [
      "openstack",
      "openstack$PRODUCT$horizon"
    ]
  },
  "epss": {
    "score": 0.0046
  },
  "mitre": {
    "cpes": [
      "cpe:2.3:a:openstack:horizon:*:*:*:*:*:*:*:*"
    ],
    "created": "2026-06-17T14:12:20.715000+00:00",
    "description": "OpenStack Horizon before 25.7.4 produces scripts for OpenStack RC file downloading that may have a crafted project name with shell metacharacters. NOTE: some parties consider this a security hardening opportunity to address certain types of user error, not a vulnerability.",
    "metrics": {
      "cvssV2_0": {},
      "cvssV3_0": {},
      "cvssV3_1": {
        "score": 6,
        "vector": "CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:L"
      },
      "cvssV4_0": {}
    },
    "mitre_repo_path": "cves/2026/55xxx/CVE-2026-55748.json",
    "references": [
      "https://launchpad.net/bugs/2152240",
      "https://wiki.openstack.org/wiki/OSSN/OSSN-0097"
    ],
    "title": null,
    "updated": "2026-06-17T15:40:12.791000+00:00",
    "vendors": [
      "openstack",
      "openstack$PRODUCT$horizon"
    ],
    "weaknesses": [
      "CWE-78"
    ]
  },
  "nvd": {
    "cpes": [
      "cpe:2.3:a:openstack:horizon:*:*:*:*:*:*:*:*"
    ],
    "created": "2026-06-17T15:17:02.503000+00:00",
    "description": "OpenStack Horizon before 25.7.4 produces scripts for OpenStack RC file downloading that may have a crafted project name with shell metacharacters. NOTE: some parties consider this a security hardening opportunity to address certain types of user error, not a vulnerability.",
    "metrics": {
      "cvssV2_0": {},
      "cvssV3_0": {},
      "cvssV3_1": {
        "score": 6.0,
        "vector": "CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:L"
      },
      "cvssV4_0": {}
    },
    "nvd_repo_path": "2026/CVE-2026-55748.json",
    "references": [
      "https://launchpad.net/bugs/2152240",
      "https://wiki.openstack.org/wiki/OSSN/OSSN-0097"
    ],
    "title": null,
    "updated": "2026-09-22T15:41:27.873000+00:00",
    "vendors": [
      "openstack",
      "openstack$PRODUCT$horizon"
    ],
    "weaknesses": [
      "CWE-78"
    ]
  },
  "opencve": {
    "changes": [
      {
        "created": "2026-06-18T04:45:00+00:00",
        "data": [
          {
            "details": {
              "new": "OpenStack Horizon before 25.7.4 produces scripts for OpenStack RC file downloading that may have a crafted project name with shell metacharacters. NOTE: some parties consider this a security hardening opportunity to address certain types of user error, not a vulnerability.",
              "old": null
            },
            "type": "description"
          },
          {
            "details": [
              "openstack",
              "openstack$PRODUCT$horizon"
            ],
            "type": "first_time"
          },
          {
            "details": {
              "added": [
                "CWE-78"
              ],
              "removed": []
            },
            "type": "weaknesses"
          },
          {
            "details": {
              "added": [
                "cpe:2.3:a:openstack:horizon:*:*:*:*:*:*:*:*"
              ],
              "removed": []
            },
            "type": "cpes"
          },
          {
            "details": {
              "added": [
                "openstack",
                "openstack$PRODUCT$horizon"
              ],
              "removed": []
            },
            "type": "vendors"
          },
          {
            "details": {
              "added": [
                "https://launchpad.net/bugs/2152240",
                "https://wiki.openstack.org/wiki/OSSN/OSSN-0097"
              ],
              "removed": []
            },
            "type": "references"
          },
          {
            "details": {
              "added": {
                "cvssV3_1": {
                  "score": 6,
                  "vector": "CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:L"
                }
              },
              "removed": {},
              "updated": {}
            },
            "type": "metrics"
          }
        ],
        "id": "54eeaa40-a53f-4ce8-95e5-00b20098e5fb"
      },
      {
        "created": "2026-06-18T16:45:00+00:00",
        "data": [
          {
            "details": {
              "new": "OpenStack Horizon: OpenStack Horizon: Information disclosure or integrity compromise via crafted project name with shell metacharacters",
              "old": null
            },
            "type": "title"
          },
          {
            "details": {
              "added": [
                "https://nvd.nist.gov/vuln/detail/CVE-2026-55748",
                "https://www.cve.org/CVERecord?id=CVE-2026-55748"
              ],
              "removed": []
            },
            "type": "references"
          },
          {
            "details": {
              "added": {},
              "removed": {},
              "updated": {
                "threat_severity": {
                  "new": "Moderate",
                  "old": null
                }
              }
            },
            "type": "metrics"
          }
        ],
        "id": "ce355d12-3719-41e8-8f57-d63363813f34"
      },
      {
        "created": "2026-06-19T12:30:00+00:00",
        "data": [
          {
            "details": {
              "added": {
                "ssvc": {
                  "options": {
                    "Automatable": "no",
                    "Exploitation": "none",
                    "Technical Impact": "total"
                  },
                  "version": "2.0.3"
                }
              },
              "removed": {},
              "updated": {}
            },
            "type": "metrics"
          }
        ],
        "id": "763542db-d41b-4be4-9689-aa1bd9ab8847"
      }
    ],
    "cpes": {
      "data": [
        "cpe:2.3:a:openstack:horizon:*:*:*:*:*:*:*:*"
      ],
      "providers": [
        "mitre",
        "nvd"
      ]
    },
    "created": {
      "data": "2026-06-17T14:12:20+00:00",
      "provider": "redhat"
    },
    "description": {
      "data": "OpenStack Horizon before 25.7.4 produces scripts for OpenStack RC file downloading that may have a crafted project name with shell metacharacters. NOTE: some parties consider this a security hardening opportunity to address certain types of user error, not a vulnerability.",
      "provider": "mitre"
    },
    "metrics": {
      "cvssV2_0": {
        "data": {},
        "provider": null
      },
      "cvssV3_0": {
        "data": {},
        "provider": null
      },
      "cvssV3_1": {
        "data": {
          "score": 6,
          "vector": "CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:L"
        },
        "provider": "mitre"
      },
      "cvssV4_0": {
        "data": {},
        "provider": null
      },
      "epss": {
        "data": {
          "score": 0.0046
        },
        "provider": "first"
      },
      "kev": {
        "data": {},
        "provider": null
      },
      "ssvc": {
        "data": {
          "options": {
            "Automatable": "no",
            "Exploitation": "none",
            "Technical Impact": "total"
          },
          "version": "2.0.3"
        },
        "provider": "vulnrichment"
      },
      "threat_severity": {
        "data": "Moderate",
        "provider": "redhat"
      }
    },
    "references": {
      "data": [
        "https://launchpad.net/bugs/2152240",
        "https://nvd.nist.gov/vuln/detail/CVE-2026-55748",
        "https://wiki.openstack.org/wiki/OSSN/OSSN-0097",
        "https://www.cve.org/CVERecord?id=CVE-2026-55748"
      ],
      "providers": [
        "mitre",
        "nvd",
        "redhat"
      ]
    },
    "title": {
      "data": "OpenStack Horizon: OpenStack Horizon: Information disclosure or integrity compromise via crafted project name with shell metacharacters",
      "provider": "redhat"
    },
    "updated": {
      "data": "2026-06-18T21:45:04.768019+00:00",
      "provider": "enrichment"
    },
    "vendors": {
      "data": [
        "openstack",
        "openstack$PRODUCT$horizon"
      ],
      "providers": [
        "mitre",
        "nvd",
        "enrichment"
      ]
    },
    "weaknesses": {
      "data": [
        "CWE-78"
      ],
      "providers": [
        "mitre",
        "nvd",
        "redhat"
      ]
    }
  },
  "redhat": {
    "cpes": [],
    "created": "2026-06-17T14:12:20+00:00",
    "description": "A flaw was found in OpenStack Horizon. This vulnerability allows a highly privileged remote attacker, with user interaction, to craft a project name containing shell metacharacters. When scripts for OpenStack RC file downloading are produced, these metacharacters may be processed, potentially leading to information disclosure or integrity compromise. This issue is considered by some as a security hardening opportunity rather than a direct vulnerability.",
    "metrics": {
      "cvssV2_0": {},
      "cvssV3_0": {},
      "cvssV3_1": {
        "score": 6.0,
        "vector": "CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:L"
      },
      "threat_severity": "Moderate"
    },
    "redhat_repo_path": "2026/CVE-2026-55748.json",
    "references": [
      "https://launchpad.net/bugs/2152240",
      "https://nvd.nist.gov/vuln/detail/CVE-2026-55748",
      "https://wiki.openstack.org/wiki/OSSN/OSSN-0097",
      "https://www.cve.org/CVERecord?id=CVE-2026-55748"
    ],
    "title": "OpenStack Horizon: OpenStack Horizon: Information disclosure or integrity compromise via crafted project name with shell metacharacters",
    "updated": "2026-06-17T14:12:20+00:00",
    "vendors": [],
    "weaknesses": [
      "CWE-78"
    ]
  },
  "vulnrichment": {
    "cpes": [],
    "created": "2026-06-17T14:12:20.715000+00:00",
    "description": "OpenStack Horizon before 25.7.4 produces scripts for OpenStack RC file downloading that may have a crafted project name with shell metacharacters. NOTE: some parties consider this a security hardening opportunity to address certain types of user error, not a vulnerability.",
    "metrics": {
      "cvssV2_0": {},
      "cvssV3_0": {},
      "cvssV3_1": {},
      "cvssV4_0": {},
      "kev": {},
      "ssvc": {
        "options": {
          "Automatable": "no",
          "Exploitation": "none",
          "Technical Impact": "total"
        },
        "version": "2.0.3"
      }
    },
    "references": [],
    "title": null,
    "updated": "2026-06-17T15:40:08.717000+00:00",
    "vendors": [],
    "vulnrichment_repo_path": "2026/55xxx/CVE-2026-55748.json",
    "weaknesses": []
  }
}