CVE-2026-93858

NameCVE-2026-93858
DescriptionIn OpenStack Mistral through 23.0.0, the std.ssh_proxied action passes a caller-supplied proxy_command value directly to paramiko.ProxyCommand() before any SSH connection to a gateway or target host is attempted. An authenticated project member can use the standard action-execution API to submit an arbitrary local command as proxy_command; paramiko starts that command as a subprocess on the executor host under the executor's own service account, independent of whether the SSH connection itself ever succeeds. Only Mistral deployments that permit the std.ssh_proxied action, the default configuration, are affected.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
Debian Bugs1150346

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
mistral (PTS)bookworm, bookworm (security)15.0.0-1+deb12u1vulnerable
trixie (security), trixie20.0.0-2+deb13u1vulnerable
forky23.0.0-1vulnerable
sid23.0.0-2fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
mistralsource(unstable)23.0.0-21150346

Notes

https://launchpad.net/bugs/2162100
https://security.openstack.org/ossa/OSSA-2026-044.html

Search for package or bug name: Reporting problems