Safety vulnerability ID: 61151
The information on this page was manually curated by our Cybersecurity Intelligence Team.
bin/compile-messages.py in Django 0.95 does not quote argument strings before invoking the msgfmt program through the os.system function, which allows attackers to execute arbitrary commands via shell metacharacters in a (1) .po or (2) .mo file.
Latest version: 5.1.3
A high-level Python web framework that encourages rapid development and clean, pragmatic design.
This vulnerability has no description
Scan your Python project for dependency vulnerabilities in two minutes
Scan your application