Django Relative Path Traversal Vulnerability - CVE-2025-59682
An issue was discovered in Django 4.2 before 4.2.25 5.1 before 5.1.13 and 5.2 before 5.2.7. The django.utils.archive.extract() function used by the quotstartapp --templatequot and quotstartproject --templatequot commands allows partial directory traversal via an archive with file paths sharing a common prefix with the target directory.