THREAT OPS › Threat News › [GHSA] GHSA-8jj7-4v57-frf5 (high) — django CMS: Plugin move endpoint allows cyclic reparenting (DoS)
[GHSA] GHSA-8jj7-4v57-frf5 (high) — django CMS: Plugin move endpoint allows cyclic reparenting (DoS)
GHSA-8jj7-4v57-frf5 Severity: high CVE: CVE-2026-54623
django CMS: Plugin move endpoint allows cyclic reparenting (DoS)
### Summary The `move_plugin` admin endpoint does not prevent a plugin from being reparented under itself or one of its own descendants. Doing so creates a cycle in the plugin tree, after which the recursive descendant/ancestor SQL queries loop without terminating, stalling
Indicators of compromise
- CVE-2026-54623cve
Original source: https://github.com/advisories/GHSA-8jj7-4v57-frf5