The mistral-dashboard plugin for openstack has a local file inclusion vulnerability through the 'Create Workbook' feature that may result in disclosure of arbitrary local files content.
https://review.opendev.org/c/openstack/python-mistralclient/+/800950
https://review.opendev.org/c/openstack/mistral-dashboard/+/800952
https://lists.debian.org/debian-lts-announce/2025/12/msg00003.html
https://lists.debian.org/debian-lts-announce/2025/12/msg00002.html
https://bugzilla.redhat.com/show_bug.cgi?id=2417321