CyberSecurityBoardThreat Intel · CVEs · Products
Critical CVEs

CVE-2026-15307: GeoDjango Spatial Lookup File Write / RCE

August 5, 2026

CVE-2026-15307 is a high-severity vulnerability in Django's GeoDjango component. Spatial lookups accept str and dict values that can be passed to GDALRaster, potentially allowing file writes or network requests, which can lead to remote code execution. The documented admin path requires a staff user with view permission on a model containing a spatial field. Fixed in Django 6.0.8 and 5.2.17.