PT-2026-94121 · Pypi+1 · Djust+1
CVE-2026-61594
·
Published
2026-09-16
·
Updated
2026-09-17
CVSS v3.1
9.1
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
djust versions prior to 1.0.7
Description
The live WebSocket transport authorizes a mount using the
check view auth function instead of the standard Django View.dispatch() chain. This causes standard Django authorization mechanisms—such as LoginRequiredMixin, PermissionRequiredMixin, UserPassesTestMixin, @method decorator(login required, name="dispatch"), and custom dispatch() guards—as well as the djust admin extension staff gate, to be bypassed over WebSocket connections. While these guards are enforced during the initial HTTP GET request, they are not applied to the WebSocket transport where events and state flow. Consequently, an anonymous or under-privileged client can establish a WebSocket connection to mount views, including administrative list, create, change, and delete functions, and dispatch their respective handlers.Recommendations
Update djust to version 1.0.7.
As a temporary workaround, gate views using djust's
login required, permission required, or check permissions attributes instead of HTTP-only mixins or decorators.Exploit
Fix
Missing Authentication
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Django
Djust