Low severity3.1NVD Advisory· Published Oct 1, 2025· Updated Jun 17, 2026
CVE-2025-59682
CVE-2025-59682
Description
An issue was discovered in Django 4.2 before 4.2.25, 5.1 before 5.1.13, and 5.2 before 5.2.7. The django.utils.archive.extract() function, used by the "startapp --template" and "startproject --template" commands, allows partial directory traversal via an archive with file paths sharing a common prefix with the target directory.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
djangoPyPI | >= 4.2, < 4.2.25 | 4.2.25 |
djangoPyPI | >= 5.1, < 5.1.13 | 5.1.13 |
djangoPyPI | >= 5.2, < 5.2.7 | 5.2.7 |
Affected products
13cpe:2.3:a:djangoproject:django:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:djangoproject:django:*:*:*:*:*:*:*:*range: >=4.2.0,<4.2.25
- (no CPE)range: 4.2
- osv-coords11 versionspkg:apk/chainguard/awxpkg:bitnami/djangopkg:pypi/djangopkg:rpm/opensuse/python-Django&distro=openSUSE%20Leap%2015.6pkg:rpm/opensuse/python-Django&distro=openSUSE%20Leap%2016.0pkg:rpm/opensuse/python-Django&distro=openSUSE%20Tumbleweedpkg:rpm/opensuse/python-Django4&distro=openSUSE%20Tumbleweedpkg:rpm/opensuse/python-Django5&distro=openSUSE%20Tumbleweedpkg:rpm/opensuse/python-Django6&distro=openSUSE%20Tumbleweedpkg:rpm/suse/python-Django&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Package%20Hub%2015%20SP6pkg:rpm/suse/python-Django&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Package%20Hub%2015%20SP7
< 24.6.1-r17+ 10 more
- (no CPE)range: < 24.6.1-r17
- (no CPE)range: >= 4.2.0, < 4.2.25
- (no CPE)range: >= 4.2, < 4.2.25
- (no CPE)range: < 4.2.11-150600.3.33.1
- (no CPE)range: < 5.2.4-bp160.3.1
- (no CPE)range: < 5.2.7-1.1
- (no CPE)range: < 4.2.25-1.1
- (no CPE)range: < 5.2.16-1.1
- (no CPE)range: < 6.0-1.1
- (no CPE)range: < 4.2.11-150600.3.33.1
- (no CPE)range: < 4.2.11-150600.3.33.1
Patches
Vulnerability mechanics
References
10- docs.djangoproject.com/en/dev/releases/security/nvdVendor Advisory
- github.com/advisories/GHSA-q95w-c7qg-hrffghsaADVISORY
- groups.google.com/g/django-announcenvdRelease NotesVendor AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2025-59682ghsaADVISORY
- www.djangoproject.com/weblog/2025/oct/01/security-releases/nvdRelease NotesVendor Advisory
- www.openwall.com/lists/oss-security/2025/10/01/3nvdWEB
- docs.djangoproject.com/en/dev/releases/securityghsaWEB
- github.com/django/django/commit/43d84aef04a9e71164c21a74885996981857e66eghsaWEB
- github.com/django/django/commit/924a0c092e65fa2d0953fd1855d2dc8786d94de2ghsaWEB
- www.djangoproject.com/weblog/2025/oct/01/security-releasesghsaWEB
News mentions
0No linked articles in our index yet.