PT-2026-93746 · Djust · Djust
CVE-2026-61590
·
Published
2026-09-16
·
Updated
2026-09-16
CVSS v3.1
7.4
High
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
djust versions prior to 1.0.7
Description
Observability endpoints expose live view/session state and a remote method-invocation surface via the
eval handler function. In configurations where DEBUG is enabled and the optional localhost restriction middleware is not installed, clients from non-localhost addresses can read live application state and invoke handlers remotely.Recommendations
Update to version 1.0.7.
Set
DEBUG=False in production environments.
Restrict access to observability endpoints to prevent exposure to untrusted networks.Exploit
Fix
Exposure of Resource to Wrong Sphere
Missing Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Djust