PT-2026-81390 · Djust · Djust

·

CVE-2026-55571

·

Published

2026-08-25

·

Updated

2026-09-10

CVSS v3.1

8.2

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N
Name of the Vulnerable Software and Affected Versions djust versions prior to 1.0.4
Description An authentication bypass exists in the LiveViewConsumer when a view is restricted by login required, permission required, or a redirecting on mount hook. In these cases, the handle mount() function sends a navigation frame to the client but fails to close the WebSocket connection or clear the self.view instance variable. While standard browsers follow the redirect, a raw WebSocket client can ignore it and maintain an open socket. Since the handle event() function does not re-verify authentication or authorization, an unauthenticated client can send event frames to invoke @event handler methods, potentially leading to unauthorized sensitive data reads or mutations. This behavior also affects the handle live redirect mount() function.
Recommendations Update to version 1.0.4. As a temporary workaround, ensure that every @event handler on a gated LiveView independently verifies that the request user is authenticated and authorized. As an alternative workaround, override the consumer's handle mount() function to execute await self.close(code=4403) after emitting an authentication redirect. Enable the defense-in-depth control by setting LIVEVIEW CONFIG['reauth on event'] = True to re-run authentication checks on every event for gated views.

Exploit

Fix

Improper Authorization

Missing Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-55571
GHSA-XX4J-W367-7247
PYSEC-2026-3829

Affected Products

Djust