OpenStack Vitrage: Unauthorized Access to the Host can Lead to Eval Injection
Critical severity
GitHub Reviewed
Published
Feb 27, 2026
to the GitHub Advisory Database
•
Updated Mar 5, 2026
Package
Affected versions
>= 15.0.0.0rc1, < 15.0.1
>= 14.0.0.0rc1, < 14.0.1
>= 13.0.0.0rc1, < 13.0.1
< 12.0.1
Patched versions
15.0.1
14.0.1
13.0.1
12.0.1
Description
Published by the National Vulnerability Database
Feb 27, 2026
Published to the GitHub Advisory Database
Feb 27, 2026
Reviewed
Feb 28, 2026
Last updated
Mar 5, 2026
In the query parser in OpenStack Vitrage before 12.0.1, 13.0.0, 14.0.0, and 15.0.0, a user allowed to access the Vitrage API may trigger code execution on the Vitrage service host as the user the Vitrage service runs under. This may result in unauthorized access to the host and further compromise of the Vitrage service. All deployments exposing the Vitrage API are affected. This occurs in _create_query_function in vitrage/graph/query.py.
References