Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-rmxr-45gj-889w | OpenStack Ironic Python Agent Includes Functionality from Untrusted Control Sphere |
Sat, 09 May 2026 00:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | ironic-python-agent: OpenStack ironic-python-agent: Arbitrary code execution via malicious image | |
| Weaknesses | CWE-78 | |
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Mon, 04 May 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Openstack ironic Python Agent
|
|
| CPEs | cpe:2.3:a:openstack:ironic_python_agent:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Openstack ironic Python Agent
|
Sun, 03 May 2026 23:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Openstack
Openstack ironic-python-agent |
|
| Vendors & Products |
Openstack
Openstack ironic-python-agent |
Fri, 01 May 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 01 May 2026 08:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An issue was discovered in OpenStack ironic-python-agent 1.0.0 through 11.5.0. Ironic Python Agent (IPA) sometimes executes grub-install from within a chroot of the deployed partition image, leading to code execution in the case of a malicious image. | |
| Weaknesses | CWE-829 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-05-01T14:13:33.387Z
Reserved: 2026-05-01T00:00:00.000Z
Link: CVE-2026-43003
Updated: 2026-05-01T14:13:27.290Z
Status : Analyzed
Published: 2026-05-01T09:16:17.440
Modified: 2026-05-04T18:28:28.253
Link: CVE-2026-43003
OpenCVE Enrichment
Updated: 2026-05-09T02:15:06Z
Github GHSA