Junglewise Threat Intelligence

CVE-2025-59681: Django SQL injection in column aliases on MySQL and MariaDB

CVE-2025-59681 · Severity: high · CVSS 7.1 · Published 2025-10-01

Technologies: Django Software Foundation Django, Django (PyPI). Vendors: Django Software Foundation, PyPI.

Executive brief

Django, a popular web framework, is vulnerable to a security flaw that could allow an attacker to execute unauthorized database commands. This issue occurs when the application uses specific database functions to organize or summarize data on MySQL or MariaDB databases. If exploited, an attacker could potentially access or modify sensitive information stored in the database, leading to data breaches or unauthorized data manipulation.

Technical details

A SQL injection vulnerability exists in Django's QuerySet.annotate(), QuerySet.alias(), QuerySet.aggregate(), and QuerySet.extra() methods. The root cause is improper neutralization of special elements in column aliases when using dictionary expansion (**kwargs) on MySQL and MariaDB backends. An attacker with low privileges can exploit this over the network by providing a specially crafted dictionary to these methods, potentially leading to unauthorized data access or modification. The vulnerability is mitigated by high attack complexity as it requires specific application-level coding patterns. Patches are available in versions 4.2.25, 5.1.13, and 5.2.7.

Affected products

  • Django Software Foundation Django >= 4.2, < 4.2.25
  • Django Software Foundation Django >= 5.1, < 5.1.13
  • Django Software Foundation Django >= 5.2, < 5.2.7

Timeline

  • 2025-10-01: disclosed
  • 2025-10-01: advisory
  • 2025-10-01: patched

References

Related threats