VDB
EN

PYSEC-2026-328

django-s3file is vulnerable to relative path traversal

상세

### Impact `S3FileMiddleware` is vulnerable to relative path traversal attacks, where an attacker can use a modified request to escape pre-signed upload locations and have the Django application load files from random locations into `request.FILES`

Depending on how files are handled, this may lead to confidentiality and integrity issues.

### Patches Django-S3File urges all users to update to a patched version >=7.0.2.

이 버전이 영향받나요?

사용 중인 패키지 버전을 입력하면 즉시 평가합니다.

영향 패키지

PyPI / django-s3file
최초 영향 버전: 0 수정 버전: 7.0.2
수정 pip install --upgrade 'django-s3file>=7.0.2'

참고