VDB
Sign up
HIGH8.1

PYSEC-2026-505

Injection vulnerability that affects ironic-discoverd

Quick fix

PYSEC-2026-505 — python-ironic-inspector-client: upgrade to the fixed version with the command below.

pip install --upgrade 'python-ironic-inspector-client>=0.2.5'

Details

OpenStack Ironic Inspector (aka ironic-inspector or ironic-discoverd), when debug mode is enabled, might allow remote attackers to access the Flask console and execute arbitrary Python code by triggering an error.

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI/python-ironic-inspector-client
Introduced in: 0Fixed in: 0.2.5
Fixpip install --upgrade 'python-ironic-inspector-client>=0.2.5'

References