CVE-2026-24010: Django Path Traversal Insecure Join

Constructing paths with `os.path.join` using user input can lead to path traversal vulnerabilities (CWE-22). If string prefix or similar checks are applied before resolving the final path, attackers can bypass access controls by tricking the prefix check while traversing directories later. Use `django.utils._os.safe_join` to securely combine paths so that th

Provally CuratedPublic repositoryHighMedium confidenceVerifiedApache-2.0Python
greprules fetch cve-2026-24010-django-path-traversal-insecure-join --engine opengrep

Description

Constructing paths with `os.path.join` using user input can lead to path traversal vulnerabilities (CWE-22). If string prefix or similar checks are applied before resolving the final path, attackers can bypass access controls by tricking the prefix check while traversing directories later. Use `django.utils._os.safe_join` to securely combine paths so that th