PYSEC-2026-630
Dashboard / Vulnerabilities / PYSEC-2026-630
PYSEC-2026-630
Summary: Django Arbitrary Code Execution
Details: `bin/compile-messages.py` in Django 0.95 does not quote argument strings before invoking the msgfmt program through the os.system function, which allows attackers to execute arbitrary commands via shell metacharacters in a (1) .po or (2) .mo file.
References: https://nvd.nist.gov/vuln/detail/CVE-2007-0404, https://github.com/django/django/commit/518d406e53, https://github.com/django/django/commit/a132d411c6986418ee6c0edc331080aa792fee6e, https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=407519, https://exchange.xforce.ibmcloud.com/vulnerabilities/31627, https://github.com/django/django, http://code.djangoproject.com/changeset/3592, https://pypi.org/project/django, https://github.com/advisories/GHSA-qc99-g3wm-hgxr
Affected packages
Package
Name: django
Purl: pkg:pypi/django
Affected ranges
Type: ECOSYSTEM
Events:
