The CVSS 9.4 rating for CVE-2026-45272 obscures a more dangerous reality: once you reach the admin panel, achieving code execution is not an injection challenge—it's a direct code generation failure. The application writes SOCIAL_AUTH key names directly into a Python source file (auto.py) without escaping, meaning you close the settings dictionary with a malformed key like `key\