CVE-2026-15307: Server-side file-write and request forgery via spatial lookups in Django, 8.8 rating 🔥
Recently disclosed Django vulnerability allows an attacker to write a file to disk (in some cases enabling remote code execution) or issue a network request as the Django process user. This flaw is reachable by staff users with view permissions on any registered model containing a spatial field.
Search at Netlas.io:
👉 Link: https://nt.ls/xa9dB
👉 Dork: tag.name:"django"
Vendor's advisory:
https://www.djangoproject.com/weblog/2026/aug/04/security-releases/
Post #606
506

- ❤ 2
- 🔥 1