LOW3.1
PYSEC-2026-1296
Django vulnerable to partial directory traversal via archives
Quick fix
PYSEC-2026-1296 — django: upgrade to the fixed version with the command below.
pip install --upgrade 'django>=4.2.25'Details
An issue was discovered in Django 4.2 before 4.2.25, 5.1 before 5.1.13, and 5.2 before 5.2.7. The django.utils.archive.extract() function, used by the "startapp --template" and "startproject --template" commands, allows partial directory traversal via an archive with file paths sharing a common prefix with the target directory.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://nvd.nist.gov/vuln/detail/CVE-2025-59682[ADVISORY]
- https://github.com/django/django/commit/43d84aef04a9e71164c21a74885996981857e66e[WEB]
- https://github.com/django/django/commit/924a0c092e65fa2d0953fd1855d2dc8786d94de2[WEB]
- https://docs.djangoproject.com/en/dev/releases/security[WEB]
- https://github.com/django/django[PACKAGE]
- https://groups.google.com/g/django-announce[WEB]
- https://www.djangoproject.com/weblog/2025/oct/01/security-releases[WEB]
- http://www.openwall.com/lists/oss-security/2025/10/01/3[WEB]
- https://pypi.org/project/django[PACKAGE]
- https://github.com/advisories/GHSA-q95w-c7qg-hrff[ADVISORY]