PT-2026-105798 · Pypi · Djust

Publicado

2026-10-01

·

Atualizado

2026-10-01

CVSS v3.1

7.1

Alta

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N

Impact

djust's per-object authorization (get object + has object permission, ADR-017) was enforced on the WebSocket mount and event paths but not on three other render entry points: (a) the initial HTTP GET render, (b) SPA url change navigation, and (c) {% live render %} embedded child views. An authenticated user could therefore view (and on some paths act on) an object they are not authorized for by loading the page directly, navigating to it via SPA url-change, or composing it as an embedded child — a classic IDOR / broken object-level access control on object-scoped views.

Patches

Fixed in djust 1.0.7. All render entry points now route through a shared enforce object permission chokepoint: HTTP GET returns 403, url change emits a permission denied frame and skips the render, and {% live render %} (eager + lazy) refuses the embed. Views without a custom get object are unaffected (no-op).

Workarounds

No reliable workaround short of upgrading. Do not expose object-scoped views through the HTTP-GET / url change / live render paths until patched.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

PYSEC-2026-4041

Produtos afetados

Djust