{"id":"CVE-2026-55748","aliases":["PYSEC-2026-2519"],"url":"https://o3.security/vulnerability/CVE-2026-55748","summary":"OpenStack Horizon RC file generation does not escape special characters in project names","details":"OpenStack Horizon before 25.7.4 produces scripts for OpenStack RC file downloading that may have a crafted project name with shell metacharacters. NOTE: some parties consider this a security hardening opportunity to address certain types of user error, not a vulnerability.","published":"2026-06-17T18:35:56Z","modified":"2026-09-10T03:50:48.488432476Z","cvss":{"score":6,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:L"},"epss":{"score":0.00218,"percentile":0.12434,"asOf":"2026-09-17"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"PyPI","name":"horizon","fixedVersion":null}],"fix":null,"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-55748"},{"type":"PACKAGE","url":"https://github.com/openstack/horizon"},{"type":"WEB","url":"https://launchpad.net/bugs/2152240"},{"type":"WEB","url":"https://wiki.openstack.org/wiki/OSSN/OSSN-0097"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-09-10T03:50:48.488432476Z"}}