OpenStack Skyline before 5.0.1, 6.0.0, and 7.0.0 has a DOM-based Cross-Site Scripting (XSS) vulnerability in the console because document.write is used unsafely, which is relevant in scenarios where administrators use the console web interface to view instance console logs.
https://www.openwall.com/lists/oss-security/2026/04/09/30
https://security.openstack.org/ossa/OSSA-2026-006.html