GHSA-pghf-347x-c2gj
CRITICALGHSA-pghf-347x-c2gj is a critical-severity (CVSS 9.8) SQL Injection vulnerability in django-debug-toolbar. O3 Security confirms whether GHSA-pghf-347x-c2gj is actually reachable in your code before you act, and blocks exploitation at runtime until you patch.
SQL Injection via in django-debug-toolbar
Real-World Exposure
django-debug-toolbar🐍django-debug-toolbar🐍django-debug-toolbarReal-time download stats are indexed for npm and PyPI packages. This vulnerability affects PyPI packages — download data is not available via public APIs for these ecosystems.
Description
Impact
With Django Debug Toolbar attackers are able to execute SQL by changing the raw_sql input of the SQL explain, analyze or select forms and submitting the form.
NOTE: This is a high severity issue for anyone using the toolbar in a production environment.
Generally the Django Debug Toolbar team only maintains the latest version of django-debug-toolbar, but an exception was made because of the high severity of this issue.
Patches
Please upgrade to one of the following versions, depending on the major version you're using:
- Version 1.x: django-debug-toolbar 1.11.1
- Version 2.x: django-debug-toolbar 2.2.1
- Version 3.x: django-debug-toolbar 3.2.1
For more information
If you have any questions or comments about this advisory:
- Open an issue in the django-debug-toolbar repo (Please NO SENSITIVE INFORMATION, send an email instead!)
- Email us at [email protected]
Affected Packages
| Ecosystem | Package | Vulnerable range | Fix |
|---|---|---|---|
| 🐍PyPI | django-debug-toolbar | ≥ 0.10.0&&< 1.11.1 | 1.11.1 |
| 🐍PyPI | django-debug-toolbar | ≥ 2.0a1&&< 2.2.1 | 2.2.1 |
| 🐍PyPI | django-debug-toolbar | ≥ 3.0a1&&< 3.2.1 | 3.2.1 |
Detection & mitigation playbook
Open-source dependencyDetect
Scan your dependency tree (package-lock.json, pnpm-lock.yaml, requirements.txt, go.sum, etc.) for django-debug-toolbar. O3's reachability analysis confirms whether the vulnerable code path is actually invoked in your application, so you act on real exposure instead of every transitive match.
Fix
Update django-debug-toolbar to 1.11.1 or later, then make sure no transitive (indirect) dependency still pins the vulnerable range — O3 confirms GHSA-pghf-347x-c2gj is resolved across your whole dependency graph.
Workarounds
If you can't upgrade right away: gate or disable the affected feature, validate untrusted input at the boundary, and avoid passing attacker-controlled data into the vulnerable path. O3's runtime protection blocks exploitation in production as an interim safeguard until the upgrade lands.
How O3 protects you
O3 pinpoints whether GHSA-pghf-347x-c2gj is reachable in your code and exactly where to fix it, then blocks exploitation in production at runtime until the patched version is deployed.
Tailored to GHSA-pghf-347x-c2gj. Runtime protection reduces exposure until a permanent patch is applied and verified — it complements patching, it doesn't replace it.
Frequently Asked Questions
Is GHSA-pghf-347x-c2gj in your dependencies?
O3 detects GHSA-pghf-347x-c2gj across PyPI dependencies and uses function-level reachability to confirm whether the vulnerable code path is actually reachable — not just present. No false positives.