PT-2026-93747 · Pypi · Djust
CVE-2026-61598
·
Published
2026-09-16
·
Updated
2026-09-16
CVSS v4.0
7.1
High
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
djust versions prior to 1.0.7
Description
The
djust.mixins.model binding.ModelBindingMixin provides a default update model event handler that allows a client to set any public, existing view attribute via a WebSocket request using the parameters field and value. The mechanism only rejects names starting with an underscore or those present in a small denylist of framework internals (FORBIDDEN MODEL FIELDS). Because the allowed model fields allowlist is optional and defaults to allowing all fields, an attacker can manipulate business logic, authorization flags, or ownership state (e.g., is admin or account id) that the developer did not intend to expose. The system also performs type coercion to match the target attribute's type, facilitating the attack.Recommendations
Update to version 1.0.7.
As a temporary workaround, explicitly set
allowed model fields on every view using dj-model (or subclassing LiveView) to the minimal list of bindable fields.
Avoid storing authorization or ownership state in public view attributes that share the view with dj-model bindings.Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Djust