—
PYSEC-2026-1627
Mezzanine allows attackers to bypass access control mechanisms
Details
An issue in Mezzanine v6.0.0 allows attackers to bypass access control mechanisms in the admin panel via a crafted request.
Are you affected?
Enter the version of the package you're using.
Affected packages
PyPI/mezzanine
Introduced in:
0No fixed version published yet for mezzanine (pip). Pin to a known-safe version or switch to an alternative.
References
- https://nvd.nist.gov/vuln/detail/CVE-2024-25169[ADVISORY]
- https://github.com/shenhav12/CVE-2024-25169-Mezzanine-v6.0.0[WEB]
- https://github.com/stephenmcd/mezzanine[PACKAGE]
- https://ibb.co/JKh4hmD[WEB]
- https://ibb.co/Pt9qd8t[WEB]
- https://ibb.co/hLLPTVp[WEB]
- https://ibb.co/rfrKj3r[WEB]
- https://pypi.org/project/mezzanine[PACKAGE]
- https://github.com/advisories/GHSA-qp56-82vp-xqgv[ADVISORY]