{"id":"PYSEC-2026-1849","summary":"OpenStack's Mistral Client has a local file inclusion vulnerability","details":"The mistral-dashboard plugin for openstack has a local file inclusion vulnerability through the 'Create Workbook' feature that may result in disclosure of arbitrary local files content.","aliases":["CVE-2021-4472","GHSA-75hx-6r6j-hw56"],"modified":"2026-07-07T17:47:51.799268501Z","published":"2026-07-07T16:03:10.958192Z","references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2021-4472"},{"type":"WEB","url":"https://access.redhat.com/security/cve/CVE-2021-4472"},{"type":"WEB","url":"https://bugs.launchpad.net/horizon/+bug/1931558"},{"type":"WEB","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2417321"},{"type":"WEB","url":"https://lists.debian.org/debian-lts-announce/2025/12/msg00002.html"},{"type":"WEB","url":"https://lists.debian.org/debian-lts-announce/2025/12/msg00003.html"},{"type":"PACKAGE","url":"https://opendev.org/openstack/mistral-dashboard"},{"type":"WEB","url":"https://review.opendev.org/c/openstack/mistral-dashboard/+/800952"},{"type":"WEB","url":"https://review.opendev.org/c/openstack/python-mistralclient/+/800950"},{"type":"PACKAGE","url":"https://pypi.org/project/python-mistralclient"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-75hx-6r6j-hw56"}],"affected":[{"package":{"name":"python-mistralclient","ecosystem":"PyPI","purl":"pkg:pypi/python-mistralclient"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"4.3.0"}]}],"versions":["0","0.0.1","0.0.2","0.0.3","0.0.4","0.1","0.1.1","0.2.0","0.3.0","1.0.0","1.0.0.0b1","1.0.1","1.0.2","1.1.0","1.2.0","2.0.0","2.1.0","2.1.1","2.1.2","3.0.0","3.0.1","3.0.2","3.1.0","3.1.1","3.1.2","3.1.3","3.1.4","3.1.5","3.10.0","3.2.0","3.3.0","3.4.0","3.5.0","3.6.0","3.6.1","3.7.0","3.8.0","3.8.1","3.9.0","4.0.0","4.0.1","4.1.0","4.1.1","4.2.0"],"database_specific":{"source":"https://github.com/pypa/advisory-database/blob/main/vulns/python-mistralclient/PYSEC-2026-1849.yaml"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"}]}