PT-2026-94122 · Pypi · Djust

CVE-2026-61596

·

Published

2026-09-16

·

Updated

2026-09-17

CVSS v3.1

7.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N
Name of the Vulnerable Software and Affected Versions djust versions prior to 1.0.7
Description An issue exists in the per-object authorization mechanism involving the get object() and has object permission() functions. While authorization was enforced on WebSocket mount and event paths, it was missing from the initial HTTP GET render, SPA url change navigation, and {% live render %} embedded child views. This results in an Insecure Direct Object Reference (IDOR), where an authenticated user can view or interact with objects they are not authorized to access by loading the page directly, using SPA navigation, or composing it as an embedded child. This specifically affects object-scoped views; views without a custom get object() function are not impacted.
Recommendations Update djust to version 1.0.7. Do not expose object-scoped views through HTTP GET, url change, or live render paths until the update is applied.

Exploit

Fix

IDOR

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-61596
GHSA-C7C5-5J6R-Q957

Affected Products

Djust