PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-15920 Djangoproject CVE debrief

An issue was discovered in Django 5.2 before 5.2.17 and 6.0 before 6.0.8. `django.contrib.admin.utils.display_for_field()` renders `URLField` values as clickable links in the admin without validating the URL. A value stored with an unsafe scheme is displayed as a link on changelist and read-only admin pages, which allows cross-site scripting against staff users who click the link. Exploitation requires the unsafe value to already be stored in the database. `URLField` validation through a `ModelForm` or the admin rejects unsafe schemes, so this affects applications that persist `URLField` data without running model validation, for example through direct queryset writes, deserialization, or bulk import of untrusted input. Django would like to thank Egor Saltykov for reporting this issue. The CVE record was published on 2026-08-04T17:16:46.733Z and has not been modified since then. The NVD entry is currently Analyzed. To verify and mitigate this vulnerability, defenders should review the official Django security release notes and patches, validate URLField values before rendering them in the admin interface, and use ModelForm or admin validation to reject unsafe URL schemes.

Vendor
Djangoproject
Product
Django
CVSS
MEDIUM 5.1
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-04
Original CVE updated
2026-08-17
Advisory published
2026-08-04
Advisory updated
2026-08-17

Who should care

Django developers and administrators who use the Django admin interface are at risk and should take immediate action to protect their applications. This includes reviewing and applying available patches for Django versions 5.2 and 6.0, validating URLField values before rendering them in the admin interface, and using ModelForm or admin validation to reject unsafe URL schemes. Additionally, staff users who interact with the Django admin interface are at risk of cross-site scripting attacks when clicking on links rendered from unvalidated URLField values.

Technical summary

The `django.contrib.admin.utils.display_for_field()` function renders URLField values as clickable links in the admin interface without proper validation. This allows for cross-site scripting attacks against staff users who click on links rendered from unvalidated URLField values stored in the database. The vulnerability affects Django versions 5.2 before 5.2.17 and 6.0 before 6.0.8. To mitigate this vulnerability, developers should validate URLField values before rendering them in the admin interface and use ModelForm or admin validation to reject unsafe URL schemes.

Defensive priority

Staff users who interact with the Django admin interface are at risk of cross-site scripting attacks when clicking on links rendered from unvalidated URLField values.

Recommended defensive actions

  • Review and apply available patches for Django versions 5.2 and 6.0
  • Validate URLField values before rendering them in the admin interface
  • Use ModelForm or admin validation to reject unsafe URL schemes
  • Monitor for suspicious activity on staff user accounts
  • Consider implementing additional security measures for the admin interface

Evidence notes

The CVE record and NVD details indicate that Django versions 5.2 before 5.2.17 and 6.0 before 6.0.8 are affected by a cross-site scripting vulnerability in the admin interface due to improper validation of URLField values. The vulnerability allows for cross-site scripting attacks against staff users who click on links rendered from unvalidated URLField values stored in the database. To verify and mitigate this vulnerability, defenders should review the official Django security release notes and patches, validate URLField values before rendering them in the admin interface, and use ModelForm or admin validation to reject unsafe URL schemes.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-15920 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-15920

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-15920 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-15920

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Mitigation or vendor reference

    Unverified legacy reference

    URL: https://docs.djangoproject.com/en/dev/releases/security/

    6a34fbeb-21d4-45e7-8e0a-62b95bc12c92 - Patch, Vendor Advisory

  • Mitigation or vendor reference

    Unverified legacy reference

    URL: https://github.com/django/django/commit/13debb622a32720bda1bccda7622fd14fbf3931b

    6a34fbeb-21d4-45e7-8e0a-62b95bc12c92 - Patch

  • Mitigation or vendor reference

    Unverified legacy reference

    URL: https://github.com/django/django/commit/47511a21026cdd721d8fbf8571cc079bc38bb46d

    6a34fbeb-21d4-45e7-8e0a-62b95bc12c92 - Patch

  • Mitigation or vendor reference

    Unverified legacy reference

    URL: https://github.com/django/django/commit/5a260d309a4c8010c2ebda24eb758a5d95e2508a

    6a34fbeb-21d4-45e7-8e0a-62b95bc12c92 - Patch

  • Mitigation or vendor reference

    Unverified legacy reference

    URL: https://github.com/django/django/commit/b9adb81339cc418f8f56b1050cca6dfec3ab6349

    6a34fbeb-21d4-45e7-8e0a-62b95bc12c92 - Patch

  • Source reference

    Unverified legacy reference

    URL: https://groups.google.com/g/django-announce

    6a34fbeb-21d4-45e7-8e0a-62b95bc12c92 - Mailing List

  • Mitigation or vendor reference

    Unverified legacy reference

    URL: https://www.djangoproject.com/weblog/2026/aug/04/security-releases/

    6a34fbeb-21d4-45e7-8e0a-62b95bc12c92 - Vendor Advisory

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.