PT-2026-93747 · Pypi · Djust

CVE-2026-61598

·

Published

2026-09-16

·

Updated

2026-09-16

CVSS v4.0

7.1

High

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions djust versions prior to 1.0.7
Description The djust.mixins.model binding.ModelBindingMixin provides a default update model event handler that allows a client to set any public, existing view attribute via a WebSocket request using the parameters field and value. The mechanism only rejects names starting with an underscore or those present in a small denylist of framework internals (FORBIDDEN MODEL FIELDS). Because the allowed model fields allowlist is optional and defaults to allowing all fields, an attacker can manipulate business logic, authorization flags, or ownership state (e.g., is admin or account id) that the developer did not intend to expose. The system also performs type coercion to match the target attribute's type, facilitating the attack.
Recommendations Update to version 1.0.7. As a temporary workaround, explicitly set allowed model fields on every view using dj-model (or subclassing LiveView) to the minimal list of bindable fields. Avoid storing authorization or ownership state in public view attributes that share the view with dj-model bindings.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-61598
GHSA-CC7C-9JFF-58WJ

Affected Products

Djust