PT-2026-94117 · Pypi · Djust

CVE-2026-61588

·

Published

2026-09-16

·

Updated

2026-09-19

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions djust versions prior to 1.0.7
Description When a Django Model instance is assigned to a public view attribute, the software serializes it to the client without a sensitive-field denylist. This results in the exposure of sensitive data to the browser, including password hashes, tokens, personally identifiable information (PII), and privilege flags such as is staff and is superuser. Since exposing model objects to templates is a standard pattern in this software, credentials and PII can be leaked without the developer's knowledge.
Recommendations Update to version 1.0.7. As a temporary workaround, keep Model instances on private attributes and expose only the specific fields needed.

Exploit

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-61588
GHSA-PVG3-6Q9J-MJ3X

Affected Products

Djust