GHSA-c2xx-cjmh-9q8f: Medium severity pip/wagtail vulnerability

Published Aug 20, 2026
·
Updated

Impact

The Documents and Images API V2 incorrectly listed items in descendants of private collections, which should inherit the view restrictions defined on their ancestors. A user with access to the API could see the filename and name of documents and images in these descendant collections.

Patches

Patched versions have been released as Wagtail 7.0.9, 7.3.4, 7.4.3 and 8.0rc2.

Workarounds

Site owners using Wagtail's API can avoid the vulnerability by adding authentication to the Documents and Images APIs.

Acknowledgements

Many thanks to Ta Duc Thien for reporting this issue.

For more information If you have any questions or comments about this advisory:

Visit Wagtail's support channels Email us at security@wagtail.org (view our security policy for more information).

Affected Software

4 affected componentsFixes available
pip/wagtail=8.0rc1
8.0rc2
pip/wagtail>=7.4<7.4.3
7.4.3
pip/wagtail>=7.1<7.3.4
7.3.4
pip/wagtail<7.0.9
7.0.9

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade pip/wagtail to a version that resolves this vulnerability.

    Fixed in 8.0rc2
  2. Upgrade

    Upgrade pip/wagtail to a version that resolves this vulnerability.

    Fixed in 7.4.3
  3. Upgrade

    Upgrade pip/wagtail to a version that resolves this vulnerability.

    Fixed in 7.3.4
  4. Upgrade

    Upgrade pip/wagtail to a version that resolves this vulnerability.

    Fixed in 7.0.9
  5. Upgrade

    Upgrade wagtail to a version that resolves this vulnerability.

    Fixed in 7.0.9
  6. Upgrade

    Upgrade wagtail to a version that resolves this vulnerability.

    Fixed in 7.3.4
  7. Upgrade

    Upgrade wagtail to a version that resolves this vulnerability.

    Fixed in 7.4.3
  8. Upgrade

    Upgrade wagtail to a version that resolves this vulnerability.

    Fixed in 8.0rc2
  9. Configuration

    Enable authentication for the Documents and Images APIs (so only authenticated access can enumerate filenames/names in descendant collections).

    Wagtail Documents and Images API V2 authentication = enabled

Event History

Aug 20, 2026
Advisory Published
via GitHub·06:45 PM
Data Sourced
via GitHub·06:45 PM
DescriptionSeverityWeaknessAffected Software

Frequently Asked Questions

1

Who can retrieve the exposed metadata?

A user with access to Wagtail’s API V2 can see the filename and name of documents and images stored in descendant collections of private collections. The issue affects the Documents and Images APIs.

2

Does exploitation require authentication or user interaction?

No authentication or user interaction is required according to the supplied severity vector. Exposure depends on the affected Documents and Images API endpoints being accessible.

3

Which versions contain fixes?

Fixed releases are Wagtail 7.0.9, 7.3.4, 7.4.3, and 8.0rc2.

4

What can be done if an upgrade cannot be applied immediately?

Configure authentication for the Documents and Images APIs. This prevents unauthenticated API users from viewing the affected document and image metadata.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203