Executive brief
Django's admin interface displays URLField values as clickable links without validating that the URL uses a safe scheme (like http or https). An attacker who stores a malicious URL with an unsafe scheme (like javascript:) directly in the database can trick admin staff into clicking it, executing arbitrary JavaScript in their browser session. This could lead to theft of admin credentials or unauthorized actions.
Technical details
The vulnerability exists in `django.contrib.admin.utils.display_for_field()`, which renders URLField values as HTML links in the admin interface without validating the URL scheme. An attacker can store unsafe URLs (e.g., `javascript:alert('xss')`) directly in the database, bypassing normal URLField validation by using direct queryset writes, deserialization, or bulk import. When admin staff view the changelist or read-only pages and click the link, the unsafe scheme executes arbitrary JavaScript in their authenticated session. The attack requires pre-existing malicious data in the database but no authentication or special privileges to exploit once stored.
Affected products
- Django Django 5.2 before 5.2.17, 6.0 before 6.0.8
Timeline
- 2026-08-04: disclosed