{"id":"PYSEC-2026-630","summary":"Django Arbitrary Code Execution","details":"`bin/compile-messages.py` in Django 0.95 does not quote argument strings before invoking the msgfmt program through the os.system function, which allows attackers to execute arbitrary commands via shell metacharacters in a (1) .po or (2) .mo file.","aliases":["CVE-2007-0404","GHSA-qc99-g3wm-hgxr"],"modified":"2026-07-06T08:00:11.808832399Z","published":"2026-07-02T14:13:20.006998Z","references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2007-0404"},{"type":"WEB","url":"https://github.com/django/django/commit/518d406e53"},{"type":"WEB","url":"https://github.com/django/django/commit/a132d411c6986418ee6c0edc331080aa792fee6e"},{"type":"WEB","url":"https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=407519"},{"type":"WEB","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/31627"},{"type":"PACKAGE","url":"https://github.com/django/django"},{"type":"WEB","url":"http://code.djangoproject.com/changeset/3592"},{"type":"PACKAGE","url":"https://pypi.org/project/django"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-qc99-g3wm-hgxr"}],"affected":[{"package":{"name":"django","ecosystem":"PyPI","purl":"pkg:pypi/django"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0.95"},{"fixed":"1.0"}]}],"versions":["0.95"],"database_specific":{"source":"https://github.com/pypa/advisory-database/blob/main/vulns/django/PYSEC-2026-630.yaml"}}],"schema_version":"1.7.5"}