GHSA-3vrh-m9w7-v94f

    Dashboard / Vulnerabilities / GHSA-3vrh-m9w7-v94f

    GHSA-3vrh-m9w7-v94f

    Published: 20 Aug 2026Last Modified: 20 Aug 2026

    Summary: Wagtail: Improper restriction handling on Pages admin API

    Details: ### Impact The internal Pages admin [API](https://docs.wagtail.org/en/stable/advanced_topics/api/index.html) incorrectly returns page fields without access control when they are declared in `api_fields`. A user with access to the Wagtail admin can use this API to fetch draft and live page fields’ contents that are part of `api_fields` on the base page model (title, slug, seo_title, search_description), as well as all custom fields declared in `api_fields`. The vulnerability is not exploitable by an ordinary site visitor without access to the Wagtail admin. ### Patches Patched versions have been released as Wagtail 7.0.9, 7.3.4, 7.4.3 and 8.0rc2. ### Workarounds Site owners unable to upgrade can apply the fix by overriding the relevant method on `PagesAdminAPIViewSet` to patch all vulnerable admin API endpoints: ```python # wagtail_hooks.py or AppConfig.ready() from wagtail.admin.api.views import PagesAdminAPIViewSet from wagtail.permissions import page_permission_policy def _restricted_get_base_queryset(self): return page_permission_policy.explorable_instances(self.request.user) PagesAdminAPIViewSet.get_base_queryset = _restricted_get_base_queryset ``` ### Acknowledgements Many thanks to xuliang@QAX for reporting this issue. ### For more information If you have any questions or comments about this advisory: - Visit Wagtail's [support channels](https://docs.wagtail.org/en/stable/support.html) - Email us at [[email protected]](mailto:[email protected]) (view our [security policy](https://github.com/wagtail/wagtail/security/policy) for more information).

    Affected packages

    Package

    Name: wagtail

    Purl: pkg:pypi/wagtail

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 0
    Fixed -7.0.9

    Affected versions

    0.1

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High