Home
LOW: 3.1 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:NDefault status
unknown
4.2 (custom) before 4.2.25
affected
5.1 (custom) before 5.1.13
affected
5.2 (custom) before 5.2.7
affected
Description
An issue was discovered in Django 4.2 before 4.2.25, 5.1 before 5.1.13, and 5.2 before 5.2.7. The django.utils.archive.extract() function, used by the "startapp --template" and "startproject --template" commands, allows partial directory traversal via an archive with file paths sharing a common prefix with the target directory.
Problem types
CWE-23 Relative Path Traversal
Product status
4.2 (custom) before 4.2.25
5.1 (custom) before 5.1.13
5.2 (custom) before 5.2.7
References
www.openwall.com/lists/oss-security/2025/10/01/3
docs.djangoproject.com/en/dev/releases/security/
groups.google.com/g/django-announce
www.djangoproject.com/weblog/2025/oct/01/security-releases/