Description
An issue was discovered in Django 4.2 before 4.2.24, 5.1 before 5.1.12, and 5.2 before 5.2.6. FilteredRelation is subject to SQL injection in column aliases, using a suitably crafted dictionary, with dictionary expansion, as the **kwargs passed QuerySet.annotate() or QuerySet.alias().
Exploits (5)
nomisec
WORKING POC
2 stars
by loic-houchi · poc
https://github.com/loic-houchi/Django-faille-CVE-2025-57833_test
References (6)
Scores
CVSS v3
7.1
EPSS
0.0002
EPSS Percentile
5.7%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:L/A:N
Lab Environment
COMMUNITY
Community Lab
+2 more repos
Details
CWE
CWE-89
Status
published
Products (2)
djangoproject/django
4.2 - 4.2.24
pypi/Django
0 - 4.2.24PyPI
Published
Sep 03, 2025
Tracked Since
Feb 18, 2026