LOW 3.1 PyPI
Django vulnerable to partial directory traversal via archives
GHSA-q95w-c7qg-hrff · BIT-django-2025-59682 · CVE-2025-59682 · PYSEC-2026-1296
Published · Modified
AI SAST
Find this class of vulnerability in your own code
Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.
Description
An issue was discovered in Django 4.2 before 4.2.25, 5.1 before 5.1.13, and 5.2 before 5.2.7. The django.utils.archive.extract() function, used by the "startapp --template" and "startproject --template" commands, allows partial directory traversal via an archive with file paths sharing a common prefix with the target directory.
References
- ADVISORY https://nvd.nist.gov/vuln/detail/CVE-2025-59682
- WEB https://github.com/django/django/commit/43d84aef04a9e71164c21a74885996981857e66e
- WEB https://github.com/django/django/commit/924a0c092e65fa2d0953fd1855d2dc8786d94de2
- WEB https://docs.djangoproject.com/en/dev/releases/security
- PACKAGE https://github.com/django/django
- WEB https://groups.google.com/g/django-announce
- WEB https://www.djangoproject.com/weblog/2025/oct/01/security-releases
- WEB http://www.openwall.com/lists/oss-security/2025/10/01/3
Ready to move
Start Securing
Free, no credit card | First findings in minutes