djust 为 Django 提供类似 Phoenix LiveView 的反应式服务端渲染,并借助 Rust 实现高性能。在 1.0.7 版本之前,WebSocket 的 和 通过 重建 ,但未包含 ,导致在活动路径(live path)上, 默认返回 。这使得基于 Host/子域名/域名的 在活动路径上错误解析租户——返回 ,而 HTTP 路径能正确解析租户。当 时,租户作用域的管理器会返回未加限制的行(导致跨租户数据泄露);在默认设置下,则返回空的查询集(导致多租户功能失效)。该问题已在 djust 1.0.
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-61594 | 9.1 CRITICAL | djust has an authorization bypass on the WebSocket/SSE mount path |
| CVE-2026-61599 | 8.8 HIGH | djust has an unauthenticated arbitrary module import via the WebSocket/SSE view-mount path |
| CVE-2026-61593 | 8.1 HIGH | djust has Cross-Site Request Forgery on the Server-Sent-Events transport: a cross-origin p |
| CVE-2026-61591 | 8.1 HIGH | djust: Unsigned client state snapshot is restored as trusted view state (privilege escalat |
| CVE-2026-61595 | 7.7 HIGH | djust: Multi-tenant isolation fails open on the WebSocket/SSE path, disclosing other tenan |
| CVE-2026-61590 | 7.4 HIGH | djust's observability endpoints are network-exposed: the localhost gate is an opt-in middl |
| CVE-2026-61592 | 7.4 HIGH | djust: SSE sessions are not bound to the authenticated user; the client-chosen session_id |
| CVE-2026-61598 | 7.1 HIGH | Client mass-assignment of arbitrary view attributes via the default dj-model update_model |
| CVE-2026-61596 | 7.1 HIGH | djust has broken object-level access control (IDOR) |
| CVE-2026-61588 | 6.5 MEDIUM | djust's Django model serialization has no sensitive-field denylist: password hashes, privi |
| CVE-2026-61597 | 5.1 MEDIUM | djust is vulnerable to stored/reflected XSS via javascript: URLs in built-in component tem |
No comments yet