PT-2026-93746 · Djust · Djust

CVE-2026-61590

·

Published

2026-09-16

·

Updated

2026-09-16

CVSS v3.1

7.4

High

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions djust versions prior to 1.0.7
Description Observability endpoints expose live view/session state and a remote method-invocation surface via the eval handler function. In configurations where DEBUG is enabled and the optional localhost restriction middleware is not installed, clients from non-localhost addresses can read live application state and invoke handlers remotely.
Recommendations Update to version 1.0.7. Set DEBUG=False in production environments. Restrict access to observability endpoints to prevent exposure to untrusted networks.

Exploit

Fix

Exposure of Resource to Wrong Sphere

Missing Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-61590
GHSA-8G2F-G3GQ-5RJV

Affected Products

Djust