CVE-2026-15920
Received Received - Intake

XSS in Django Admin via Unsafe URLField Links

Vulnerability report for CVE-2026-15920, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-04

Last updated on: 2026-08-04

Assigner: Django Software Foundation

Description

An issue was discovered in Django 5.2 before 5.2.17 and 6.0 before 6.0.8. `django.contrib.admin.utils.display_for_field()` renders `URLField` values as clickable links in the admin without validating the URL. A value stored with an unsafe scheme is displayed as a link on changelist and read-only admin pages, which allows cross-site scripting against staff users who click the link. Exploitation requires the unsafe value to already be stored in the database. `URLField` validation through a `ModelForm` or the admin rejects unsafe schemes, so this affects applications that persist `URLField` data without running model validation, for example through direct queryset writes, deserialization, or bulk import of untrusted input. Django would like to thank Egor Saltykov for reporting this issue.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-04
Last Modified
2026-08-04
Generated
2026-08-04
AI Q&A
2026-08-04
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
django django to 5.2.17 (exc)
django django to 6.0.8 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-83 The product does not neutralize or incorrectly neutralizes "javascript:" or other URIs from dangerous attributes within tags, such as onmouseover, onload, onerror, or style.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a cross-site scripting (XSS) issue in Django's admin interface. It occurs because URLField values are rendered as clickable links without validating the URL scheme. If a malicious value with an unsafe scheme like 'javascript:' or 'data:' is stored in the database, it appears as a link in the admin panel. When an admin user clicks it, the script executes in their authenticated session.

Detection Guidance

To detect this vulnerability, check if your Django application uses URLField values in the admin interface without proper validation. Inspect the admin changelist and read-only pages for any displayed links with unsafe schemes like 'javascript:' or 'data:'. Review the code for direct queryset writes or bulk imports that bypass model validation.

Impact Analysis

This vulnerability allows attackers to execute malicious scripts in the context of an authenticated admin user's session. If exploited, it could lead to unauthorized actions, data theft, or session hijacking. Attackers need to already have stored unsafe URLs in the database, which may occur through direct database writes or bulk imports.

Compliance Impact

This vulnerability could impact compliance with GDPR and HIPAA by enabling cross-site scripting (XSS) attacks in authenticated admin sessions. If exploited, it may lead to unauthorized data access or manipulation, violating confidentiality and integrity requirements under these regulations.

Mitigation Strategies

Upgrade Django to version 5.2.17 or later for the 5.2.x branch, or 6.0.8 or later for the 6.0.x branch. Ensure all URLField data is validated using Django's URLValidator before rendering in the admin. Review and sanitize any existing unsafe URL values in your database.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-15920. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart