PT-2026-94119 · Djust · Djust
CVE-2026-61591
·
Published
2026-09-16
·
Updated
2026-09-16
CVSS v3.1
8.1
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
djust versions prior to 1.0.7
Description
For views that utilize state snapshots, the
state json snapshot embedded in the client page is restored upon reconnection as trusted view state without an integrity check. This allows a client to modify the unsigned state json and return it in the reconnect mount frame to inject arbitrary view attributes. Examples of exploitation include changing is admin to True or altering account id and balance, leading to privilege escalation or tampering with business state stored in public view attributes.Recommendations
Update to version 1.0.7.
As a temporary workaround, disable state snapshots and avoid storing authorization or ownership state in public view attributes.
Exploit
Fix
Insufficient Verification of Data Authenticity
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Djust