Debian Linux Security Advisory 3230-1 - James P. Turk discovered that the ReST renderer in django-markupfield, a custom Django field for easy use of markup in text fields, didn't disable the ..raw directive, allowing remote attackers to include arbitrary files.
3270e5081886088b7ed8f4115a4706ecb72ef1ab0109663405f9e4dee0cff5b9