Hi,
The following vulnerability was published for django-haystack.
CVE-2026-105315[0]:
| A vulnerability has been found in django-haystack up to 3.3.0.
| Affected is the function _to_python of the file
| haystack/backends/elasticsearch_backend.py of the component
| more_like_this Template Tag Handler. Such manipulation of the
| argument result_class leads to improper neutralization of directives
| in dynamically evaluated code. The attack can be launched remotely.
| The exploit has been disclosed to the public and may be used.
| Upgrading to version 3.4.0 is able to address this issue. The name
| of the patch is eb05f193c9771a68dcc8cfac6674a0d48a52ee9d. It is
| suggested to upgrade the affected component.
If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.
For further information see:
[0] https://security-tracker.debian.org/tracker/CVE-2026-105315
https://www.cve.org/CVERecord?id=CVE-2026-105315
[1] https://github.com/django-haystack/django-haystack/security/advisories/GHSA-r3hx-x5rh-p9vv
[2] https://github.com/django-haystack/django-haystack/commit/eb05f193c9771a68dcc8cfac6674a0d48a52ee9d
Please adjust the affected versions in the BTS as needed.
Regards,
Salvatore