PT-2026-93886 · Pypi · Djust
Published
2026-09-16
·
Updated
2026-09-16
CVSS v3.1
7.4
High
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N |
Impact
djust's observability endpoints expose live view/session state and a remote method-invocation surface (
eval handler). The localhost restriction was an opt-in middleware that the documented setup omits; the views themselves enforced only DEBUG. In the misconfigured-but-documented scenario (DEBUG on, middleware not installed) a non-localhost client could read live application state and invoke handlers remotely.Patches
Fixed in djust 1.0.7. The localhost restriction is enforced in-view on every observability endpoint (no longer dependent on a separately-installed middleware), and
eval handler is restricted; gated requests receive a non-disclosing response.Workarounds
Ensure
DEBUG=False in production, and do not expose the observability endpoints to untrusted networks.Fix
Missing Authentication
Exposure of Resource to Wrong Sphere
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Djust