Djust 为 Django 提供类 Phoenix LiveView 的响应式服务器端渲染能力,并借助 Rust 实现高性能。在版本 1.0.7 之前,SSE(Server-Sent Events)中用于客户端向服务器发送数据的 POST 端点被标记为 ,且用于建立 SSE 连接的 GET 流端点未进行 Origin 检查。因此,跨源页面可以劫持携带受害者 Cookie 认证的 SSE 会话:攻击者可迫使受害者的浏览器 GET 流地址(从而以受害者身份创建并挂载一个 LiveView 实例),随后通过设置 向消息
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-61595 | 7.7 HIGH | djust: Multi-tenant isolation fails open on the WebSocket/SSE path, disclosing other tenan |
| CVE-2026-61590 | 7.4 HIGH | djust's observability endpoints are network-exposed: the localhost gate is an opt-in middl |
| CVE-2026-61598 | 7.1 HIGH | Client mass-assignment of arbitrary view attributes via the default dj-model update_model |
No comments yet