Skip to content

[Aikido] Fix security issue in django via minor version upgrade from 6.0.0 to 6.0.2 - #16

Merged
jarekwg merged 1 commit into
masterfrom
fix/aikido-security-update-packages-15806295-hgjw
Feb 9, 2026
Merged

jarekwg merged 1 commit into
masterfrom
fix/aikido-security-update-packages-15806295-hgjw

Conversation

@aikido-autofix

@aikido-autofix aikido-autofix Bot commented Feb 8, 2026

Copy link
Copy Markdown
Contributor

Patch critical SQL injection vulnerability in QuerySet.order_by() that could allow remote code execution via malicious database queries

✅ 1 CVE resolved by this upgrade

This PR will resolve the following CVEs:

Issue Severity           Description
CVE-2026-1312
HIGH
[django] SQL injection vulnerability in QuerySet.order_by() when using dictionary expansion with FilteredRelation, allowing attackers to potentially execute malicious SQL queries by manipulating column aliases containing periods.

@jarekwg
jarekwg merged commit 534e25f into master Feb 9, 2026
5 checks passed
@jarekwg
jarekwg deleted the fix/aikido-security-update-packages-15806295-hgjw branch February 9, 2026 03:08
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant