{"id":"CVE-2024-39330","aliases":["GHSA-9jmf-237g-qf46","BIT-django-2024-39330","PYSEC-2024-58"],"title":"Django Path Traversal vulnerability","summary":"Django Path Traversal vulnerability","severity":"high","cvss":7.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","vendor":"django","product":"django","ecosystem":"pip","affected":["django >= 5.0, < 5.0.7","django >= 4.2, < 4.2.14"],"patched":["django 5.0.7","django 4.2.14"],"published":"2024-07-10","updated":"2026-09-10","sourceUpdated":"2026-09-10T03:50:16.421590037Z","source":"OSV","sourceUrl":"https://osv.dev/vulnerability/GHSA-9jmf-237g-qf46","references":[{"url":"https://nvd.nist.gov/vuln/detail/CVE-2024-39330"},{"url":"https://github.com/django/django/commit/2b00edc0151a660d1eb86da4059904a0fc4e095e"},{"url":"https://github.com/django/django/commit/9f4f63e9ebb7bf6cb9547ee4e2526b9b96703270"},{"url":"https://docs.djangoproject.com/en/dev/releases/security"},{"url":"https://github.com/django/django"},{"url":"https://github.com/pypa/advisory-database/tree/main/vulns/django/PYSEC-2024-58.yaml"},{"url":"https://groups.google.com/forum/#%21forum/django-announce"},{"url":"https://security.netapp.com/advisory/ntap-20240808-0005"},{"url":"https://www.djangoproject.com/weblog/2024/jul/09/security-releases"}],"tags":["osv","pip"],"epss":0.01008,"epssPercentile":0.61579,"ingestedAt":"2026-09-12T03:13:01.684Z","slug":"CVE-2024-39330","body":"## Overview\n\nAn issue was discovered in Django 5.0 before 5.0.7 and 4.2 before 4.2.14. Derived classes of the `django.core.files.storage.Storage` base class, when they override `generate_filename()` without replicating the file-path validations from the parent class, potentially allow directory traversal via certain inputs during a `save()` call. (Built-in Storage sub-classes are unaffected.)\n\n## Affected packages\n\n- `django >= 5.0, < 5.0.7`\n- `django >= 4.2, < 4.2.14`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `django 5.0.7`\n- `django 4.2.14`","depth":"twilight","depthScore":41,"depthScoreParts":{"impact":41.3,"likelihood":0.2,"exploitation":0,"ransomware":0},"changes":[]}