PatchSiren cyber security CVE debrief
CVE-2026-15920 Djangoproject CVE debrief
An issue was discovered in Django 5.2 before 5.2.17 and 6.0 before 6.0.8. `django.contrib.admin.utils.display_for_field()` renders `URLField` values as clickable links in the admin without validating the URL. A value stored with an unsafe scheme is displayed as a link on changelist and read-only admin pages, which allows cross-site scripting against staff users who click the link. Exploitation requires the unsafe value to already be stored in the database. `URLField` validation through a `ModelForm` or the admin rejects unsafe schemes, so this affects applications that persist `URLField` data without running model validation, for example through direct queryset writes, deserialization, or bulk import of untrusted input. Django would like to thank Egor Saltykov for reporting this issue. The CVE record was published on 2026-08-04T17:16:46.733Z and has not been modified since then. The NVD entry is currently Analyzed. To verify and mitigate this vulnerability, defenders should review the official Django security release notes and patches, validate URLField values before rendering them in the admin interface, and use ModelForm or admin validation to reject unsafe URL schemes.
- Vendor
- Djangoproject
- Product
- Django
- CVSS
- MEDIUM 5.1
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-04
- Original CVE updated
- 2026-08-17
- Advisory published
- 2026-08-04
- Advisory updated
- 2026-08-17
Who should care
Django developers and administrators who use the Django admin interface are at risk and should take immediate action to protect their applications. This includes reviewing and applying available patches for Django versions 5.2 and 6.0, validating URLField values before rendering them in the admin interface, and using ModelForm or admin validation to reject unsafe URL schemes. Additionally, staff users who interact with the Django admin interface are at risk of cross-site scripting attacks when clicking on links rendered from unvalidated URLField values.
Technical summary
The `django.contrib.admin.utils.display_for_field()` function renders URLField values as clickable links in the admin interface without proper validation. This allows for cross-site scripting attacks against staff users who click on links rendered from unvalidated URLField values stored in the database. The vulnerability affects Django versions 5.2 before 5.2.17 and 6.0 before 6.0.8. To mitigate this vulnerability, developers should validate URLField values before rendering them in the admin interface and use ModelForm or admin validation to reject unsafe URL schemes.
Defensive priority
Staff users who interact with the Django admin interface are at risk of cross-site scripting attacks when clicking on links rendered from unvalidated URLField values.
Recommended defensive actions
- Review and apply available patches for Django versions 5.2 and 6.0
- Validate URLField values before rendering them in the admin interface
- Use ModelForm or admin validation to reject unsafe URL schemes
- Monitor for suspicious activity on staff user accounts
- Consider implementing additional security measures for the admin interface
Evidence notes
The CVE record and NVD details indicate that Django versions 5.2 before 5.2.17 and 6.0 before 6.0.8 are affected by a cross-site scripting vulnerability in the admin interface due to improper validation of URLField values. The vulnerability allows for cross-site scripting attacks against staff users who click on links rendered from unvalidated URLField values stored in the database. To verify and mitigate this vulnerability, defenders should review the official Django security release notes and patches, validate URLField values before rendering them in the admin interface, and use ModelForm or admin validation to reject unsafe URL schemes.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-15920 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-15920
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-15920 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-15920
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://docs.djangoproject.com/en/dev/releases/security/
6a34fbeb-21d4-45e7-8e0a-62b95bc12c92 - Patch, Vendor Advisory
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://github.com/django/django/commit/13debb622a32720bda1bccda7622fd14fbf3931b
6a34fbeb-21d4-45e7-8e0a-62b95bc12c92 - Patch
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://github.com/django/django/commit/47511a21026cdd721d8fbf8571cc079bc38bb46d
6a34fbeb-21d4-45e7-8e0a-62b95bc12c92 - Patch
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://github.com/django/django/commit/5a260d309a4c8010c2ebda24eb758a5d95e2508a
6a34fbeb-21d4-45e7-8e0a-62b95bc12c92 - Patch
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://github.com/django/django/commit/b9adb81339cc418f8f56b1050cca6dfec3ab6349
6a34fbeb-21d4-45e7-8e0a-62b95bc12c92 - Patch
-
Source reference
Unverified legacy reference
URL: https://groups.google.com/g/django-announce
6a34fbeb-21d4-45e7-8e0a-62b95bc12c92 - Mailing List
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://www.djangoproject.com/weblog/2026/aug/04/security-releases/
6a34fbeb-21d4-45e7-8e0a-62b95bc12c92 - Vendor Advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.