LOW 3.1 PyPI

Django vulnerable to partial directory traversal via archives

GHSA-q95w-c7qg-hrff · BIT-django-2025-59682 · CVE-2025-59682 · PYSEC-2026-1296

Published · Modified

AI SAST

Find this class of vulnerability in your own code

Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.

Description

An issue was discovered in Django 4.2 before 4.2.25, 5.1 before 5.1.13, and 5.2 before 5.2.7. The django.utils.archive.extract() function, used by the "startapp --template" and "startproject --template" commands, allows partial directory traversal via an archive with file paths sharing a common prefix with the target directory.

Ready to move

Start Securing

Free, no credit card | First findings in minutes