django-s3file is vulnerable to relative path traversal
Critical severity
GitHub Reviewed
Published
Apr 28, 2026
in
codingjoe/django-s3file
•
Updated May 13, 2026
Description
Published to the GitHub Advisory Database
May 5, 2026
Reviewed
May 5, 2026
Published by the National Vulnerability Database
May 12, 2026
Last updated
May 13, 2026
Impact
S3FileMiddlewareis vulnerable to relative path traversal attacks, where an attacker can use a modified request to escape pre-signed upload locations and have the Django application load files from random locations intorequest.FILESDepending on how files are handled, this may lead to confidentiality and integrity issues.
Patches
Django-S3File urges all users to update to a patched version >=7.0.2.
References