THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-8jj7-4v57-frf5 (high) — django CMS: Plugin move endpoint allows cyclic reparenting (DoS)

[GHSA] GHSA-8jj7-4v57-frf5 (high) — django CMS: Plugin move endpoint allows cyclic reparenting (DoS)

medgithub_advisoriesPublished 2026-08-24

GHSA-8jj7-4v57-frf5 Severity: high CVE: CVE-2026-54623

django CMS: Plugin move endpoint allows cyclic reparenting (DoS)

### Summary The `move_plugin` admin endpoint does not prevent a plugin from being reparented under itself or one of its own descendants. Doing so creates a cycle in the plugin tree, after which the recursive descendant/ancestor SQL queries loop without terminating, stalling

Indicators of compromise

Original source: https://github.com/advisories/GHSA-8jj7-4v57-frf5