PT-2026-94121 · Pypi+1 · Djust+1

CVE-2026-61594

·

Published

2026-09-16

·

Updated

2026-09-17

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions djust versions prior to 1.0.7
Description The live WebSocket transport authorizes a mount using the check view auth function instead of the standard Django View.dispatch() chain. This causes standard Django authorization mechanisms—such as LoginRequiredMixin, PermissionRequiredMixin, UserPassesTestMixin, @method decorator(login required, name="dispatch"), and custom dispatch() guards—as well as the djust admin extension staff gate, to be bypassed over WebSocket connections. While these guards are enforced during the initial HTTP GET request, they are not applied to the WebSocket transport where events and state flow. Consequently, an anonymous or under-privileged client can establish a WebSocket connection to mount views, including administrative list, create, change, and delete functions, and dispatch their respective handlers.
Recommendations Update djust to version 1.0.7. As a temporary workaround, gate views using djust's login required, permission required, or check permissions attributes instead of HTTP-only mixins or decorators.

Exploit

Fix

Missing Authentication

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-61594
GHSA-XHHM-F6HP-2QWJ

Affected Products

Django
Djust