Ghostwire

CVE-2025-13030: All versions of the package django-mdeditor are vulnerable to Missing Authentication for Critical Function in the image...

HIGH CVSS 7.1 Exploit Available 2 PoC

Published: April 30, 2026 | Last Modified: April 30, 2026

Description

All versions of the package django-mdeditor are vulnerable to Missing Authentication for Critical Function in the image upload endpoint. An attacker can upload malicious files and achieve arbitrary code execution since this endpoint lacks authentication protection and proper sanitisation of file names.

Ghostwire Analysis — What This Means Practically

This analysis is generated by Ghostwire from NVD, CISA KEV, EPSS, and open-source intelligence data. Verify findings through primary sources before acting.

Proof-of-Concept Exploits (2)

Security Coverage (1 articles)

References