PT-2025-23006 · Unknown · Django-Select2

Neartik

·

Published

2025-05-27

·

Updated

2025-05-28

·

CVE-2025-48383

CVSS v3.1

8.2

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N
Name of the Vulnerable Software and Affected Versions Django-Select2 versions prior to 8.4.1
Description The issue affects instances of HeavySelect2Mixin subclasses, such as the ModelSelect2MultipleWidget and ModelSelect2Widget, allowing secret access tokens to leak across requests. This can enable users to access restricted query sets and data.
Recommendations For versions prior to 8.4.1, update to version 8.4.1 to resolve the issue. As a temporary workaround, consider restricting access to instances of HeavySelect2Mixin subclasses until the update is applied.

Exploit

Fix

SSRF

Weakness Enumeration

Related Identifiers

CVE-2025-48383
GHSA-WJRH-HJ83-3WH7

Affected Products

Django-Select2