{"id":"PYSEC-2026-2519","summary":"OpenStack Horizon RC file generation does not escape special characters in project names","details":"OpenStack Horizon before 25.7.4 produces scripts for OpenStack RC file downloading that may have a crafted project name with shell metacharacters. NOTE: some parties consider this a security hardening opportunity to address certain types of user error, not a vulnerability.","aliases":["CVE-2026-55748","GHSA-6wrm-x65g-hr4p"],"modified":"2026-07-13T16:31:57.391550453Z","published":"2026-07-13T15:46:20.064057Z","references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-55748"},{"type":"PACKAGE","url":"https://github.com/openstack/horizon"},{"type":"WEB","url":"https://launchpad.net/bugs/2152240"},{"type":"WEB","url":"https://wiki.openstack.org/wiki/OSSN/OSSN-0097"},{"type":"PACKAGE","url":"https://pypi.org/project/horizon"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-6wrm-x65g-hr4p"}],"affected":[{"package":{"name":"horizon","ecosystem":"PyPI","purl":"pkg:pypi/horizon"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"25.7.3"}]}],"versions":["12.0.2","12.0.3","12.0.4","13.0.0","13.0.0.0b3","13.0.0.0rc1","13.0.0.0rc2","13.0.1","13.0.2","13.0.3","14.0.0","14.0.0.0b1","14.0.0.0b2","14.0.0.0b3","14.0.0.0rc1","14.0.0.0rc2","14.0.1","14.0.2","14.0.3","14.0.4","14.1.0","15.0.0","15.0.0.0b1","15.0.0.0b2","15.0.0.0rc1","15.0.0.0rc2","15.1.0","15.1.1","15.2.0","15.3.0","15.3.1","15.3.2","16.0.0","16.0.0.0b1","16.0.0.0b2","16.0.0.0rc1","16.0.0.0rc2","16.1.0","16.2.0","16.2.1","16.2.2","17.0.0","17.1.0","18.0.0","18.1.0","18.2.0","18.3.0","18.3.1","18.3.2","18.3.3","18.3.4","18.3.5","18.4.0","18.4.1","18.5.0","18.6.0","18.6.1","18.6.2","18.6.3","18.6.4","19.0.0","19.1.0","19.2.0","19.3.0","19.4.0","20.0.0","20.1.0","20.1.1","20.1.2","20.1.3","20.1.4","20.2.0","21.0.0","22.0.0","22.1.0","22.1.1","22.2.0","23.0.0","23.0.1","23.0.2","23.1.0","23.1.1","23.2.0","23.3.0","23.3.1","23.4.0","24.0.0","24.0.1","24.0.2","25.0.0","25.1.0","25.1.1","25.1.2","25.2.0","25.3.0","25.3.1","25.3.2","25.4.0","25.5.0","25.5.1","25.5.2","25.6.0","25.7.0","25.7.1","25.7.2","25.7.3"],"database_specific":{"source":"https://github.com/pypa/advisory-database/blob/main/vulns/horizon/PYSEC-2026-2519.yaml"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:L"}]}