{"id":"GHSA-qc99-g3wm-hgxr","summary":"Django Arbitrary Code Execution","details":"`bin/compile-messages.py` in Django 0.95 does not quote argument strings before invoking the msgfmt program through the os.system function, which allows attackers to execute arbitrary commands via shell metacharacters in a (1) .po or (2) .mo file.","aliases":["CVE-2007-0404","PYSEC-2026-630"],"modified":"2026-07-06T08:11:25.188488394Z","published":"2022-05-01T17:44:04Z","database_specific":{"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2024-05-14T17:18:37Z","nvd_published_at":"2007-01-23T00:28:00Z","cwe_ids":[]},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2007-0404"},{"type":"WEB","url":"https://github.com/django/django/commit/518d406e53"},{"type":"WEB","url":"https://github.com/django/django/commit/a132d411c6986418ee6c0edc331080aa792fee6e"},{"type":"WEB","url":"https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=407519"},{"type":"WEB","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/31627"},{"type":"PACKAGE","url":"https://github.com/django/django"},{"type":"WEB","url":"http://code.djangoproject.com/changeset/3592"}],"affected":[{"package":{"name":"django","ecosystem":"PyPI","purl":"pkg:pypi/django"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0.95"},{"fixed":"1.0"}]}],"versions":["0.95"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-qc99-g3wm-hgxr/GHSA-qc99-g3wm-hgxr.json"}}],"schema_version":"1.9.0"}