PT-2026-105804 · Pypi · Djust

Published

2026-10-01

·

Updated

2026-10-01

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

Impact

The live (WebSocket) transport authorizes a mount via check view auth, not Django's View.dispatch() chain. As a result, standard Django authorization — LoginRequiredMixin, PermissionRequiredMixin, UserPassesTestMixin, @method decorator(login required, name="dispatch"), and custom dispatch() guards — and the djust admin extension's staff gate (applied only in the HTTP as view wrapper) were enforced on the initial HTTP GET but silently bypassed over WebSocket, where all events and state flow. An anonymous or under-privileged client could open a WebSocket and mount such a view — including admin list/create/change/delete — and dispatch its handlers.

Patches

Fixed in djust 1.0.7. check view auth now honors the Django AccessMixin family on every transport; a new system check S004 fails loud at startup on auth patterns the runtime cannot safely replay (decorator/overridden-dispatch forms); and the admin base mixin declares login required = True + an active-staff check permissions gate.

Workarounds

Gate views using djust's login required / permission required / check permissions attributes (honored on all transports) rather than HTTP-only mixins/decorators.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

PYSEC-2026-4047

Affected Products

Djust