djust 漏洞描述翻译: djust 为 Django 提供类似 Phoenix LiveView 的响应式服务端渲染,并结合 Rust 实现高性能表现。在 1.0.7 版本之前,djust 的对象级权限控制( + ,对应 ADR-017)仅在 WebSocket 挂载(mount)和事件(event)路径上强制执行,却未在另外三个渲染入口点生效: (a) 初始 HTTP GET 请求的渲染, (b) SPA(单页应用)的 导航, (c) 嵌入的子视图。 因此,一个已认证的用户可能通过以下方式查看(在某些路径下甚
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-61594 | 9.1 CRITICAL | djust has an authorization bypass on the WebSocket/SSE mount path |
| CVE-2026-61599 | 8.8 HIGH | djust has an unauthenticated arbitrary module import via the WebSocket/SSE view-mount path |
| CVE-2026-61593 | 8.1 HIGH | djust has Cross-Site Request Forgery on the Server-Sent-Events transport: a cross-origin p |
| CVE-2026-61591 | 8.1 HIGH | djust: Unsigned client state snapshot is restored as trusted view state (privilege escalat |
| CVE-2026-61595 | 7.7 HIGH | djust: Multi-tenant isolation fails open on the WebSocket/SSE path, disclosing other tenan |
| CVE-2026-61590 | 7.4 HIGH | djust's observability endpoints are network-exposed: the localhost gate is an opt-in middl |
| CVE-2026-61592 | 7.4 HIGH | djust: SSE sessions are not bound to the authenticated user; the client-chosen session_id |
| CVE-2026-61598 | 7.1 HIGH | Client mass-assignment of arbitrary view attributes via the default dj-model update_model |
| CVE-2026-61588 | 6.5 MEDIUM | djust's Django model serialization has no sensitive-field denylist: password hashes, privi |
| CVE-2026-61589 | 6.3 MEDIUM | djust: WebSocket/runtime reconstructed request omits the client Host, causing host/subdoma |
| CVE-2026-61597 | 5.1 MEDIUM | djust is vulnerable to stored/reflected XSS via javascript: URLs in built-in component tem |
No comments yet