Django has patched CVE-2026-15920, a moderate-severity stored cross-site scripting flaw in the admin interface caused by unsafe rendering of URLField values. In affected versions, admin changelist views and read-only fields could automatically display stored URLs as clickable links without validating the scheme, allowing attacker-controlled values such as javascript: or data: to appear as executable links in the admin panel.
The fix adds URLValidator checks before rendering URLField values as anchors and falls back to plain-text output when validation fails, preventing unsafe schemes from being turned into links. The patch also includes tests to verify that malicious URL values are no longer rendered as anchor tags, and the issue is reported as fixed in Django 6.0.8 and 5.2.17.

See affected versions and whether adversaries are exploiting it.
2 events from the most recent confirmed update back to the earliest known activity.
Django committed a fix for CVE-2026-15920, a moderate-severity stored XSS issue in the admin caused by rendering URLField values as clickable links without validating safe URL schemes. The patch updated display_for_field() to validate URLs with URLValidator and fall back to plain-text rendering for unsafe values, and added tests covering javascript: and data: payloads.
A later reference states that the stored XSS vulnerability tracked as CVE-2026-15920 was fixed in Django releases 6.0.8 and 5.2.17. The issue affected Django admin's automatic link rendering of URLField values without scheme validation.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
reddit.com
Open sourcegithub.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.