THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-4xfr-4p46-gc6p (medium) — django CMS: Clipboard copy IDOR discloses unauthorized plugin content

[GHSA] GHSA-4xfr-4p46-gc6p (medium) — django CMS: Clipboard copy IDOR discloses unauthorized plugin content

medgithub_advisoriesPublished 2026-08-20

GHSA-4xfr-4p46-gc6p Severity: medium CVE: CVE-2026-54622

django CMS: Clipboard copy IDOR discloses unauthorized plugin content

### Summary The clipboard copy paths of the `copy_plugins` admin endpoint validate only the target (the user's own clipboard) and skip source-side authorization. A staff user can copy plugins out of a placeholder they have no permission on into their clipboard, the

Indicators of compromise

Original source: https://github.com/advisories/GHSA-4xfr-4p46-gc6p