以下是该漏洞描述的中文翻译: djust 为 Django 提供类似 Phoenix LiveView 的反应式服务端渲染,并具备 Rust 驱动的高性能特性。在 1.0.7 版本之前,djust 的可观测性端点会暴露实时的视图/会话状态以及一个远程方法调用接口( )。其中,本地主机(localhost)访问限制是一个可选安装(opt-in)的中间件,但文档中描述的默认配置并未包含该中间件;而视图本身仅强制检查 标志。在“配置错误但符合文档描述”的场景下(即 且未安装该中间件),非本地客户端也能够读取应用程序的实时
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-61593 | 8.1 HIGH | djust has Cross-Site Request Forgery on the Server-Sent-Events transport: a cross-origin p |
| CVE-2026-61595 | 7.7 HIGH | djust: Multi-tenant isolation fails open on the WebSocket/SSE path, disclosing other tenan |
| CVE-2026-61598 | 7.1 HIGH | Client mass-assignment of arbitrary view attributes via the default dj-model update_model |
No comments yet