An issue was discovered in 5.1 before 5.1.14, 4.2 before 4.2.26, and 5.2 before 5.2.8. The methods `QuerySet.filter()`, `QuerySet.exclude()`, and `QuerySet.get()`, and the class `Q()`, are subject to SQL injection when using a suitably crafted dictionary, with dictionary expansion, as the `_connector` argument. Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected. Django would like to thank cyberstan for reporting this issue.
PoC: CVE-2025-64459
CVE-2025-64459 vulnerable by design app
PoC: RedTeamBrasil-CVE-2025-64459
NEO-SQLi — exploit Django _connector SQL Injection (CVE-2025-64459) | canal RedTeam Brasil
PoC: django-cve-2025-64459
demo application showing off SQL Injection exploit in django 5.2.7
PoC: CVE-2025-64459-hunter
CVE-2025-64459-hunter
PoC: CVE-2025-64459-Exploit-PoC
CVE-2025-64459-Exploit-PoC
PoC: CVE-2025-64459-Exploit-Fix
CVE-2025-64459-Exploit-Fix
PoC: CVE-2025-64459-Poc
Vulnerability: SQL Injection via QuerySet and Q() keyword argument unpacking. CVE ID: CVE-2025-64459 Severity: Critical (CVSS 9.1) Affected Versions: Django 5.1 < 5.1.14, 4.2 < 4.2.26, and 5.2 < 5.2.8. Researcher: Cyberstan (University of Warwick)
PoC: django-connector-CVE-2025-64459-testbed
A self-contained testbed for Django CVE-2025-64459. Demonstrates QuerySet.filter() parameter injection via dictionary expansion using Docker.
PoC: Blackash-CVE-2025-64459
CVE-2025-64459
PoC: CVE-2025-64459
check if vulnerable python-django version to CVE-2025-64459 bug
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Get alerted for CVEs like this
Register your stack and get notified within minutes when a matching CVE drops.
Start monitoring free