The classifier judged this item not relevant to AI security, so it is left out of lists, feeds, the API and dataset releases. If that is wrong, report a correction on this page.
MediumVulnerability
CVE-2026-105315: A vulnerability has been found in django-haystack up to 3.3.0. Affected is the function _to_python of the file…
- Source
- NVD(opens in a new tab)
- Identifier
- CVE-2026-105315
- Published
- Record updated
Summary
A vulnerability in django-haystack up to 3.3.0 affects the function _to_python in haystack/backends/elasticsearch_backend.py, part of the more_like_this Template Tag Handler component. Manipulating the argument result_class leads to improper neutralization of directives in dynamically evaluated code, and the attack can be launched remotely. The exploit has been publicly disclosed and may be used.
Mitigation
Upgrade to version 3.4.0. The patch is eb05f193c9771a68dcc8cfac6674a0d48a52ee9d. It is suggested to upgrade the affected component.