CVE-2025-13030Disclosure(pylixm / django-mdeditor)

LOWCVSS 9.8 · CRITICAL

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

All versions of the package django-mdeditor are vulnerable to Missing Authentication for Critical Function in the image upload endpoint. An attacker can upload malicious files and achieve arbitrary code execution since this endpoint lacks authentication protection and proper sanitisation of file names.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-306

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • django-mdeditor

Threat summary

  • 3 mentions across 1 observed day

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • 3 total mentions across 1 day

Affected systems

Vendors
Products
django-mdeditor

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-04-30: 3Technical Details · 2026-04-30: 304-30
Signal classification2 categories
Disclosure
266.7%
General
133.3%
Referenced assets3 URLs
Full discourse3 posts
  • CVE@CVEnew
    Disclosure

    CVE-2025-13030 All versions of the package django-mdeditor are vulnerable to Missing Authentication for Critical Function in the image upload endpoint. An attacker can upload malici… https://www.cve.org/CVERecord?id=CVE-2025-13030

    Post summary

    The text announces a new vulnerability in django-mdeditor, describing missing authentication for the image upload endpoint, but provides no PoC, exploit code, patch, or evidence of active exploitation.

    00010464
    57.3K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2025-13030 Missing Authentication in Django-mdeditor Image Upload Endpoint Enables Arbitrary Code Execution https://vulmon.com/vulnerabilitydetails?qid=CVE-2025-13030

    Post summary

    The post announces a missing authentication flaw in Django‑mdeditor’s image upload endpoint that permits arbitrary code execution.

    00000294
    4.0K followersView on X
  • Infoflowcloud@infoflowcloud
    General

    🚨*CVE* CVE-2025-13030 All versions of the package django-mdeditor are vulnerable to Missing Authentication for Critical Function in the image upload endpoint. An attacker can upload malici… https://www.cve.org/CVERecord?id=CVE-2025-13030 ----- Traducción: CVE-2025-13030 Tod… http://infoflow.cloud`

    Post summary

    The post announces CVE-2025-13030, highlighting a missing authentication flaw in django-mdeditor’s image upload endpoint, but lacks evidence of exploitation, PoC, patch, or false‑positive claims.

    00000628
    74 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Apppylixmdjango-mdeditor---

Explore more