---
id: CVE-2025-59682
title: >-
  django: Potential partial directory-traversal via archive.extract()
  (CVE-2025-59682)
summary: >-
  A flaw was found in Django. The django.utils.archive.extract() function, used
  by startapp --templateand startproject --template, allowed partial
  directory-traversal via an archive with file paths sharing a common prefix
  with the target dir…
severity: high
cvss: 8.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'
cvssSource: vendor
cwe: CWE-22
vendor: Red Hat
product: Red Hat Ansible Automation Platform 2.5 for RHEL 8
affected:
  - openshift_service_mesh 3
  - ansible_automation_platform 2
  - certification_for_red_hat_enterprise_linux 7
  - satellite 6
  - ansible_automation_platform_2_5_for_rhel 8
  - ansible_automation_platform_2_5_for_rhel 9
  - ansible_automation_platform_2_6_for_rhel 9
  - ansible_automation_platform 2.6
  - discovery 2
patched:
  - ansible_automation_platform_2_5_for_rhel 8
  - ansible_automation_platform_2_5_for_rhel 9
  - ansible_automation_platform_2_6_for_rhel 9
  - ansible_automation_platform 2.6
  - discovery 2
published: '2025-10-01'
updated: '2026-09-21'
sourceUpdated: '2026-09-21T16:28:26+00:00'
source: CSAF
sourceUrl: 'https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-59682.json'
references:
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-59682.json
  - url: 'https://access.redhat.com/security/cve/CVE-2025-59682'
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2400450'
  - url: 'https://www.cve.org/CVERecord?id=CVE-2025-59682'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2025-59682'
  - url: 'https://access.redhat.com/errata/RHSA-2025:18979'
  - url: 'https://access.redhat.com/errata/RHSA-2025:18984'
  - url: 'https://access.redhat.com/errata/RHSA-2025:19201'
  - url: 'https://access.redhat.com/errata/RHSA-2025:19221'
  - url: 'https://access.redhat.com/errata/RHSA-2025:23196'
  - url: 'https://access.redhat.com/errata/RHSA-2026:0414'
  - url: >-
      https://github.com/django/django/commit/43d84aef04a9e71164c21a74885996981857e66e
  - url: >-
      https://github.com/django/django/commit/924a0c092e65fa2d0953fd1855d2dc8786d94de2
  - url: 'https://docs.djangoproject.com/en/dev/releases/security'
  - url: 'https://github.com/django/django'
  - url: 'https://groups.google.com/g/django-announce'
  - url: 'https://www.djangoproject.com/weblog/2025/oct/01/security-releases'
  - url: 'http://www.openwall.com/lists/oss-security/2025/10/01/3'
tags:
  - csaf
  - vex
  - red-hat
  - osv
  - pip
  - score-dispute
epss: 0.00911
epssPercentile: 0.58523
aliases:
  - GHSA-q95w-c7qg-hrff
  - BIT-django-2025-59682
  - PYSEC-2026-1296
ecosystem: pip
scores:
  vendor: 8.8
  osv: 3.1
ingestedAt: '2026-07-08T18:25:52.347Z'
---

## Overview

A flaw was found in Django. The django.utils.archive.extract() function, used by startapp --templateand startproject --template, allowed partial directory-traversal via an archive with file paths sharing a common prefix with the target directory.

## Vendor advisories

- **RHSA-2025:18979** · Red Hat · fixed in: Red Hat Ansible Automation Platform 2.5 for RHEL 8, Red Hat Ansible Automation Platform 2.5 for RHEL 9 · released 2025-10-22 · [advisory](https://access.redhat.com/errata/RHSA-2025:18979)
- **RHSA-2025:18984** · Red Hat · fixed in: Red Hat Ansible Automation Platform 2.5 for RHEL 8 · released 2025-10-22 · [advisory](https://access.redhat.com/errata/RHSA-2025:18984)
- **RHSA-2025:19201** · Red Hat · fixed in: Red Hat Ansible Automation Platform 2.6 for RHEL 9 · released 2025-10-28 · [advisory](https://access.redhat.com/errata/RHSA-2025:19201)
- **RHSA-2025:19221** · Red Hat · fixed in: Red Hat Ansible Automation Platform 2.6 · released 2025-10-28 · [advisory](https://access.redhat.com/errata/RHSA-2025:19221)
- **RHSA-2025:23196** · Red Hat · fixed in: Red Hat Ansible Automation Platform 2.6 · released 2025-12-15 · [advisory](https://access.redhat.com/errata/RHSA-2025:23196)
- **RHSA-2026:0414** · Red Hat · fixed in: Red Hat Discovery 2 · released 2026-01-08 · [advisory](https://access.redhat.com/errata/RHSA-2026:0414)
- **Red Hat VEX** · Important · affected: OpenShift Service Mesh 3, Red Hat Ansible Automation Platform 2, Red Hat Certification for Red Hat Enterprise Linux 7, Red Hat Satellite 6 · no fix planned: Red Hat Satellite 6, OpenShift Service Mesh 3, Red Hat Ansible Automation Platform 2, Red Hat Certification for Red Hat Enterprise Linux 7 · updated 2026-09-21 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-59682.json)

**django: Potential partial directory-traversal via archive.extract()** — rated Important by Red Hat. Released 2025-10-01, updated 2026-09-21.

Affected:

- OpenShift Service Mesh 3
- Red Hat Ansible Automation Platform 2
- Red Hat Certification for Red Hat Enterprise Linux 7
- Red Hat Satellite 6

Fixed:

- Red Hat Ansible Automation Platform 2.5 for RHEL 8
- Red Hat Ansible Automation Platform 2.5 for RHEL 9
- Red Hat Ansible Automation Platform 2.6 for RHEL 9
- Red Hat Ansible Automation Platform 2.6
- Red Hat Discovery 2

No fix planned:

- Red Hat Satellite 6
- OpenShift Service Mesh 3
- Red Hat Ansible Automation Platform 2
- Red Hat Certification for Red Hat Enterprise Linux 7

Not affected:

- Red Hat Ansible Automation Platform 2.5 for RHEL 8
- Red Hat Ansible Automation Platform 2.5 for RHEL 9
- Red Hat Ansible Automation Platform 2.6 for RHEL 9
- Red Hat Ansible Automation Platform 2.6
- Red Hat Discovery 2
- OpenShift Service Mesh 3
- Red Hat Ansible Automation Platform 2
- Red Hat Discovery 1
- Red Hat OpenStack Platform 16.2
- Red Hat OpenStack Platform 17.1

## Remediation

Red Hat Ansible Automation Platform https://access.redhat.com/errata/RHSA-2025:18979
Red Hat Ansible Automation Platform https://access.redhat.com/errata/RHSA-2025:18984
Red Hat Ansible Automation Platform https://access.redhat.com/errata/RHSA-2025:19201

Workarounds / mitigations:

- Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

## Package advisory (CVE-2025-59682)

Affected packages:

- `django >= 4.2, < 4.2.25`
- `django >= 5.1, < 5.1.13`
- `django >= 5.2, < 5.2.7`

Patched in:

- `django 4.2.25`
- `django 5.1.13`
- `django 5.2.7`

Source: https://osv.dev/vulnerability/GHSA-q95w-c7qg-hrff
