Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-3vrh-m9w7-v94f

Опубликовано: 20 авг. 2026
Источник: github
Github: Прошло ревью
CVSS3: 4.3

Описание

Wagtail: Improper restriction handling on Pages admin API

Impact

The internal Pages admin API incorrectly returns page fields without access control when they are declared in api_fields. A user with access to the Wagtail admin can use this API to fetch draft and live page fields’ contents that are part of api_fields on the base page model (title, slug, seo_title, search_description), as well as all custom fields declared in api_fields.

The vulnerability is not exploitable by an ordinary site visitor without access to the Wagtail admin.

Patches

Patched versions have been released as Wagtail 7.0.9, 7.3.4, 7.4.3 and 8.0rc2.

Workarounds

Site owners unable to upgrade can apply the fix by overriding the relevant method on PagesAdminAPIViewSet to patch all vulnerable admin API endpoints:

# wagtail_hooks.py or AppConfig.ready() from wagtail.admin.api.views import PagesAdminAPIViewSet from wagtail.permissions import page_permission_policy def _restricted_get_base_queryset(self): return page_permission_policy.explorable_instances(self.request.user) PagesAdminAPIViewSet.get_base_queryset = _restricted_get_base_queryset

Acknowledgements

Many thanks to xuliang@QAX for reporting this issue.

For more information

If you have any questions or comments about this advisory:

Пакеты

Наименование

wagtail

pip
Затронутые версииВерсия исправления

< 7.0.9

7.0.9

Наименование

wagtail

pip
Затронутые версииВерсия исправления

>= 7.1, < 7.3.4

7.3.4

Наименование

wagtail

pip
Затронутые версииВерсия исправления

>= 7.4, < 7.4.3

7.4.3

Наименование

wagtail

pip
Затронутые версииВерсия исправления

= 8.0rc1

8.0rc2

EPSS

Процентиль: 10%
0.002
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-280

Связанные уязвимости

CVSS3: 4.3
nvd
23 дня назад

Wagtail is an open source content management system built on Django. Prior to versions 7.0.9, 7.3.4, 7.4.3, and 8.0rc2 on their respective release lines, the internal Pages admin API returns page fields declared in api_fields without sufficient access control, allowing a user with Wagtail admin access to retrieve restricted draft and live page content. This issue is fixed in versions 7.0.9, 7.3.4, 7.4.3, and 8.0rc2.

EPSS

Процентиль: 10%
0.002
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-280