Answer in brief
CVE-2026-43003 records a High severity (CVSS 8.0) command injection vulnerability in OpenStack Ironic Python Agent Includes Functionality from Untrusted Control Sphere. The source record does not mark it as known exploited. 1 affected package is mapped in the feed.
Answer in brief
CVE-2026-43003 records a High severity (CVSS 8.0) command injection vulnerability in OpenStack Ironic Python Agent Includes Functionality from Untrusted Control Sphere. The source record does not mark it as known exploited. 1 affected package is mapped in the feed.
Update ironic-python-agent to 11.6.0 if you use the affected versions. Test the change in a non-production environment first.
Local check
hol-guard supply-chain scanCommand Injection describes the vulnerability class recorded for this advisory. The current record does not mark CVE-2026-43003 as known exploited; continue to monitor the source for status changes. The feed includes package mappings that can be checked against lockfiles and deployed manifests.
| Package | Affected range | Fixed version |
|---|---|---|
| ironic-python-agentpip | >=1.0.0,<=11.5.0 | 11.6.0 |
Fixed versions are reported by the source feed; confirm compatibility before updating.
Reported by GitHub Security Advisories (ghsa).
CVE-2026-43003 records a High severity (CVSS 8.0) command injection vulnerability in OpenStack Ironic Python Agent Includes Functionality from Untrusted Control Sphere. The source record does not mark it as known exploited. 1 affected package is mapped in the feed.
The source record does not mark it as known exploited.
Check lockfiles and deployed manifests for ironic-python-agent.
HOL Guard can help your team review package activity against supported protection paths.
Explore HOL GuardUpdate ironic-python-agent to 11.6.0 if you use the affected versions. Test the change in a non-production environment first.
Local check
hol-guard supply-chain scanCommand Injection describes the vulnerability class recorded for this advisory. The current record does not mark CVE-2026-43003 as known exploited; continue to monitor the source for status changes. The feed includes package mappings that can be checked against lockfiles and deployed manifests.
| Package | Affected range | Fixed version |
|---|---|---|
| ironic-python-agentpip | >=1.0.0,<=11.5.0 | 11.6.0 |
Fixed versions are reported by the source feed; confirm compatibility before updating.
Reported by GitHub Security Advisories (ghsa).
CVE-2026-43003 records a High severity (CVSS 8.0) command injection vulnerability in OpenStack Ironic Python Agent Includes Functionality from Untrusted Control Sphere. The source record does not mark it as known exploited. 1 affected package is mapped in the feed.
The source record does not mark it as known exploited.
Check lockfiles and deployed manifests for ironic-python-agent.
HOL Guard can help your team review package activity against supported protection paths.
Explore HOL GuardAn issue was discovered in OpenStack ironic-python-agent 1.0.0 through 11.5.0. Ironic Python Agent (IPA) sometimes executes grub-install from within a chroot of the deployed partition image, leading to code execution in the case of a malicious image.
An issue was discovered in OpenStack ironic-python-agent 1.0.0 through 11.5.0. Ironic Python Agent (IPA) sometimes executes grub-install from within a chroot of the deployed partition image, leading to code execution in the case of a malicious image.