django-debug-toolbar is vulnerable to Exposure of Sensitive Information to an Unauthorized Actor
10
Low Risk
This update adds sanitization to the debug_toolbar's Request Panel, ensuring sensitive data such as GET, POST, cookies, and session values are redacted in debug output. The RequestPanel.generate_stats method now uses a new sanitize_and_sort_request_vars utility to replace the earlier unsanitized approach. Supporting helper functions (_get_sorted_keys, _process_query_dict, _process_dict) were introduced to clean and organize request data securely.
You are affected if you are using a version that falls within the vulnerable range.
django-debug-toolbar is vulnerable to Exposure of Sensitive Information to an Unauthorized Actor in versions 1.3.0 - 5.1.0.
Upgrade the django-debug-toolbar library to the patch version.
Secure your code, cloud, and runtime environments in one central system. Find and fix vulnerabilities automatically.
No credit card required | Scan results in 32secs.
SOC 2Compliant
ISO 27001Compliant