Low severityNVD Advisory· Published Oct 1, 2025· Updated Nov 4, 2025
CVE-2025-59682
CVE-2025-59682
Description
An issue was discovered in Django 4.2 before 4.2.25, 5.1 before 5.1.13, and 5.2 before 5.2.7. The django.utils.archive.extract() function, used by the "startapp --template" and "startproject --template" commands, allows partial directory traversal via an archive with file paths sharing a common prefix with the target directory.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
djangoPyPI | >= 4.2, < 4.2.25 | 4.2.25 |
djangoPyPI | >= 5.1, < 5.1.13 | 5.1.13 |
djangoPyPI | >= 5.2, < 5.2.7 | 5.2.7 |
Affected products
11- osv-coords10 versionspkg:apk/chainguard/awxpkg:bitnami/djangopkg:pypi/djangopkg:rpm/opensuse/python-Django4&distro=openSUSE%20Tumbleweedpkg:rpm/opensuse/python-Django6&distro=openSUSE%20Tumbleweedpkg:rpm/opensuse/python-Django&distro=openSUSE%20Leap%2015.6pkg:rpm/opensuse/python-Django&distro=openSUSE%20Leap%2016.0pkg:rpm/opensuse/python-Django&distro=openSUSE%20Tumbleweedpkg:rpm/suse/python-Django&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Package%20Hub%2015%20SP6pkg:rpm/suse/python-Django&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Package%20Hub%2015%20SP7
< 24.6.1-r17+ 9 more
- (no CPE)range: < 24.6.1-r17
- (no CPE)range: >= 4.2.0, < 4.2.25
- (no CPE)range: >= 4.2, < 4.2.25
- (no CPE)range: < 4.2.25-1.1
- (no CPE)range: < 6.0-1.1
- (no CPE)range: < 4.2.11-150600.3.33.1
- (no CPE)range: < 5.2.4-bp160.3.1
- (no CPE)range: < 5.2.7-1.1
- (no CPE)range: < 4.2.11-150600.3.33.1
- (no CPE)range: < 4.2.11-150600.3.33.1
- Range: 4.2
Patches
Vulnerability mechanics
References
10- github.com/advisories/GHSA-q95w-c7qg-hrffghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2025-59682ghsaADVISORY
- www.openwall.com/lists/oss-security/2025/10/01/3ghsaWEB
- docs.djangoproject.com/en/dev/releases/securityghsaWEB
- github.com/django/django/commit/43d84aef04a9e71164c21a74885996981857e66eghsaWEB
- github.com/django/django/commit/924a0c092e65fa2d0953fd1855d2dc8786d94de2ghsaWEB
- groups.google.com/g/django-announceghsaWEB
- www.djangoproject.com/weblog/2025/oct/01/security-releasesghsaWEB
- docs.djangoproject.com/en/dev/releases/security/mitre
- www.djangoproject.com/weblog/2025/oct/01/security-releases/mitre
News mentions
0No linked articles in our index yet.