{"id":"CVE-2025-59682","title":"django: Potential partial directory-traversal via archive.extract() (CVE-2025-59682)","summary":"A flaw was found in Django. The django.utils.archive.extract() function, used by startapp --templateand startproject --template, allowed partial directory-traversal via an archive with file paths sharing a common prefix with the target dir…","severity":"high","cvss":8.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","cvssSource":"vendor","cwe":"CWE-22","vendor":"Red Hat","product":"Red Hat Ansible Automation Platform 2.5 for RHEL 8","affected":["openshift_service_mesh 3","ansible_automation_platform 2","certification_for_red_hat_enterprise_linux 7","satellite 6","ansible_automation_platform_2_5_for_rhel 8","ansible_automation_platform_2_5_for_rhel 9","ansible_automation_platform_2_6_for_rhel 9","ansible_automation_platform 2.6","discovery 2"],"patched":["ansible_automation_platform_2_5_for_rhel 8","ansible_automation_platform_2_5_for_rhel 9","ansible_automation_platform_2_6_for_rhel 9","ansible_automation_platform 2.6","discovery 2"],"published":"2025-10-01","updated":"2026-09-21","sourceUpdated":"2026-09-21T16:28:26+00:00","source":"CSAF","sourceUrl":"https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-59682.json","references":[{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-59682.json"},{"url":"https://access.redhat.com/security/cve/CVE-2025-59682"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2400450"},{"url":"https://www.cve.org/CVERecord?id=CVE-2025-59682"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2025-59682"},{"url":"https://access.redhat.com/errata/RHSA-2025:18979"},{"url":"https://access.redhat.com/errata/RHSA-2025:18984"},{"url":"https://access.redhat.com/errata/RHSA-2025:19201"},{"url":"https://access.redhat.com/errata/RHSA-2025:19221"},{"url":"https://access.redhat.com/errata/RHSA-2025:23196"},{"url":"https://access.redhat.com/errata/RHSA-2026:0414"},{"url":"https://github.com/django/django/commit/43d84aef04a9e71164c21a74885996981857e66e"},{"url":"https://github.com/django/django/commit/924a0c092e65fa2d0953fd1855d2dc8786d94de2"},{"url":"https://docs.djangoproject.com/en/dev/releases/security"},{"url":"https://github.com/django/django"},{"url":"https://groups.google.com/g/django-announce"},{"url":"https://www.djangoproject.com/weblog/2025/oct/01/security-releases"},{"url":"http://www.openwall.com/lists/oss-security/2025/10/01/3"}],"tags":["csaf","vex","red-hat","osv","pip","score-dispute"],"epss":0.00911,"epssPercentile":0.57967,"aliases":["GHSA-q95w-c7qg-hrff","BIT-django-2025-59682","PYSEC-2026-1296"],"ecosystem":"pip","scores":{"vendor":8.8,"osv":3.1},"ingestedAt":"2026-07-08T18:25:52.347Z","slug":"CVE-2025-59682","body":"## Overview\n\nA flaw was found in Django. The django.utils.archive.extract() function, used by startapp --templateand startproject --template, allowed partial directory-traversal via an archive with file paths sharing a common prefix with the target directory.\n\n## Vendor advisories\n\n- **RHSA-2025:18979** · Red Hat · fixed in: Red Hat Ansible Automation Platform 2.5 for RHEL 8, Red Hat Ansible Automation Platform 2.5 for RHEL 9 · released 2025-10-22 · [advisory](https://access.redhat.com/errata/RHSA-2025:18979)\n- **RHSA-2025:18984** · Red Hat · fixed in: Red Hat Ansible Automation Platform 2.5 for RHEL 8 · released 2025-10-22 · [advisory](https://access.redhat.com/errata/RHSA-2025:18984)\n- **RHSA-2025:19201** · Red Hat · fixed in: Red Hat Ansible Automation Platform 2.6 for RHEL 9 · released 2025-10-28 · [advisory](https://access.redhat.com/errata/RHSA-2025:19201)\n- **RHSA-2025:19221** · Red Hat · fixed in: Red Hat Ansible Automation Platform 2.6 · released 2025-10-28 · [advisory](https://access.redhat.com/errata/RHSA-2025:19221)\n- **RHSA-2025:23196** · Red Hat · fixed in: Red Hat Ansible Automation Platform 2.6 · released 2025-12-15 · [advisory](https://access.redhat.com/errata/RHSA-2025:23196)\n- **RHSA-2026:0414** · Red Hat · fixed in: Red Hat Discovery 2 · released 2026-01-08 · [advisory](https://access.redhat.com/errata/RHSA-2026:0414)\n- **Red Hat VEX** · Important · affected: OpenShift Service Mesh 3, Red Hat Ansible Automation Platform 2, Red Hat Certification for Red Hat Enterprise Linux 7, Red Hat Satellite 6 · no fix planned: Red Hat Satellite 6, OpenShift Service Mesh 3, Red Hat Ansible Automation Platform 2, Red Hat Certification for Red Hat Enterprise Linux 7 · updated 2026-09-21 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-59682.json)\n\n**django: Potential partial directory-traversal via archive.extract()** — rated Important by Red Hat. Released 2025-10-01, updated 2026-09-21.\n\nAffected:\n\n- OpenShift Service Mesh 3\n- Red Hat Ansible Automation Platform 2\n- Red Hat Certification for Red Hat Enterprise Linux 7\n- Red Hat Satellite 6\n\nFixed:\n\n- Red Hat Ansible Automation Platform 2.5 for RHEL 8\n- Red Hat Ansible Automation Platform 2.5 for RHEL 9\n- Red Hat Ansible Automation Platform 2.6 for RHEL 9\n- Red Hat Ansible Automation Platform 2.6\n- Red Hat Discovery 2\n\nNo fix planned:\n\n- Red Hat Satellite 6\n- OpenShift Service Mesh 3\n- Red Hat Ansible Automation Platform 2\n- Red Hat Certification for Red Hat Enterprise Linux 7\n\nNot affected:\n\n- Red Hat Ansible Automation Platform 2.5 for RHEL 8\n- Red Hat Ansible Automation Platform 2.5 for RHEL 9\n- Red Hat Ansible Automation Platform 2.6 for RHEL 9\n- Red Hat Ansible Automation Platform 2.6\n- Red Hat Discovery 2\n- OpenShift Service Mesh 3\n- Red Hat Ansible Automation Platform 2\n- Red Hat Discovery 1\n- Red Hat OpenStack Platform 16.2\n- Red Hat OpenStack Platform 17.1\n\n## Remediation\n\nRed Hat Ansible Automation Platform https://access.redhat.com/errata/RHSA-2025:18979\nRed Hat Ansible Automation Platform https://access.redhat.com/errata/RHSA-2025:18984\nRed Hat Ansible Automation Platform https://access.redhat.com/errata/RHSA-2025:19201\n\nWorkarounds / mitigations:\n\n- Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.\n\n## Package advisory (CVE-2025-59682)\n\nAffected packages:\n\n- `django >= 4.2, < 4.2.25`\n- `django >= 5.1, < 5.1.13`\n- `django >= 5.2, < 5.2.7`\n\nPatched in:\n\n- `django 4.2.25`\n- `django 5.1.13`\n- `django 5.2.7`\n\nSource: https://osv.dev/vulnerability/GHSA-q95w-c7qg-hrff","depth":"twilight","depthScore":49,"depthScoreParts":{"impact":48.4,"likelihood":0.2,"exploitation":0,"ransomware":0},"changes":[{"seq":208565,"id":"CVE-2025-59682","ts":1790009091848,"field":"cvss","old":"3.1","new":"8.8"},{"seq":208564,"id":"CVE-2025-59682","ts":1790009091848,"field":"severity","old":"low","new":"high"}]}