PT-2026-94118 · Pypi · Djust
CVE-2026-61589
·
Published
2026-09-16
·
Updated
2026-09-17
CVSS v3.1
6.3
Medium
| Vector | AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
djust versions prior to 1.0.7
Description
The WebSocket
handle mount function and ViewRuntime. build request method rebuild an HttpRequest using RequestFactory().get(...) without including the HTTP HOST. This causes request.get host() to default to "testserver" on the live path, leading TenantResolvers based on host, subdomain, or domain to misresolve the tenant as None. When STRICT MODE is set to False, tenant-scoped managers may return unscoped rows, resulting in cross-tenant disclosure. By default, this issue leads to broken tenancy where an empty queryset is returned.Recommendations
Update djust to version 1.0.7.
Exploit
Fix
IDOR
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Djust