Critical
github
·
GHSA-9hfw-w3f4-c4p8
OpenStack Mistral allows Arbitrary Remote Code Execution when the API is exposed
Published Jun 4, 2026
CVSS 9.9
OpenStack Mistral through 22.0.0 allows Arbitrary Remote Code Execution when the API is exposed. There are endpoints that allow code execution, which can lead to exfiltration of service credentials.
Affected AI Products
mistral