Sceawere
Vulnerability Detail
CVE-2026-105315UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Django-Haystack Arbitrary Code Execution
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 4.7
- Creation Date
- 6h ago
- Vendor
- n/a
- Product
- django-haystack
- Attack Type
- Improper Neutralization of Directives in Dynamically Evaluated Code
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L
- Attack Complexity
- LOW
Narrative and Response
Description
A vulnerability has been found in django-haystack up to 3.3.0. Affected is the function _to_python of the file haystack/backends/elasticsearch_backend.py of the component more_like_this Template Tag Handler. Such manipulation of the argument result_class leads to improper neutralization of directives in dynamically evaluated code. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 3.4.0 is able to address this issue. The name of the patch is eb05f193c9771a68dcc8cfac6674a0d48a52ee9d. It is suggested to upgrade the affected component.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "4.7",
"pubDate": "2026-10-05T13:16:52.823Z",
"pubdate": "2026-10-05T13:16:52.823Z",
"executiveSummary": "A critical vulnerability exists in django-haystack versions up to 3.3.0, specifically within the 'more_like_this' template tag handler. The vulnerability, classified as an improper neutralization of directives in dynamically evaluated code, allows for remote code execution.\nThe flaw originates from the insecure handling of the 'result_class' argument within the '_to_python' function located in 'haystack/backends/elasticsearch_backend.py'. An unauthenticated, remote attacker can manipulate this input to trigger the dynamic evaluation of arbitrary code or arbitrary class instantiation.\nThe risk is severe, as successful exploitation enables full control over the application's runtime environment, potentially leading to unauthorized data access, system compromise, or complete service disruption. Exploitation does not require prior authentication, making it highly dangerous for internet-facing applications utilizing the affected component.\nDefensive actions must focus on an immediate upgrade to version 3.4.0 or the application of the official patch referenced by commit ID eb05f193c9771a68dcc8cfac6674a0d48a52ee9d.",
"technicalDetails": "The vulnerability resides within the '_to_python' function in 'haystack/backends/elasticsearch_backend.py', which is utilized by the 'more_like_this' template tag handler. The root cause is the improper handling of the 'result_class' parameter, which is passed to the function without adequate validation or sanitization before being processed by the application's internal mechanisms.\nIn the affected versions, the 'result_class' parameter is dynamically evaluated or used in a context that allows the instantiation of arbitrary Python classes. By supplying a maliciously crafted 'result_class' argument through the template tag, an attacker can coerce the backend into instantiating unintended objects or executing arbitrary code that exists within the application's execution context.\nThe attack flow begins when an attacker identifies an endpoint or template that utilizes the 'more_like_this' feature. The attacker then crafts a request that injects a payload into the 'result_class' argument. Because the 'more_like_this' template tag handler does not implement a allowlist of permitted classes or types, the '_to_python' function proceeds to process the user-supplied string as a class reference.\nThe exploitation process is as follows: 1) The attacker identifies the target parameter exposed by the 'more_like_this' tag. 2) The attacker submits a crafted payload containing a reference to a dangerous class or a serialized object structure. 3) The 'elasticsearch_backend.py' module, specifically the '_to_python' method, receives this unvalidated string. 4) The application attempts to resolve or instantiate this string. 5) If the payload successfully resolves to a callable or class with side effects, the code within the object's initialization or subsequent method calls is executed with the privileges of the Django process.\nThis vulnerability is particularly dangerous because it allows for Remote Code Execution (RCE) without requiring specific authentication. Since the 'more_like_this' functionality is often exposed directly to end-users in search result pages, the attack surface is significant for any deployment using the default configuration of django-haystack with an Elasticsearch backend.\nThe post-exploitation impact includes the ability for an attacker to execute shell commands, access environment variables, manipulate database content, and exfiltrate sensitive configuration data, effectively granting the attacker full control over the server environment."
}