PT-2026-94117 · Pypi · Djust
CVE-2026-61588
·
Published
2026-09-16
·
Updated
2026-09-19
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
djust versions prior to 1.0.7
Description
When a Django
Model instance is assigned to a public view attribute, the software serializes it to the client without a sensitive-field denylist. This results in the exposure of sensitive data to the browser, including password hashes, tokens, personally identifiable information (PII), and privilege flags such as is staff and is superuser. Since exposing model objects to templates is a standard pattern in this software, credentials and PII can be leaked without the developer's knowledge.Recommendations
Update to version 1.0.7.
As a temporary workaround, keep
Model instances on private attributes and expose only the specific fields needed.Exploit
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Djust