PT-2026-94122 · Pypi · Djust
CVE-2026-61596
·
Published
2026-09-16
·
Updated
2026-09-17
CVSS v3.1
7.1
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
djust versions prior to 1.0.7
Description
An issue exists in the per-object authorization mechanism involving the
get object() and has object permission() functions. While authorization was enforced on WebSocket mount and event paths, it was missing from the initial HTTP GET render, SPA url change navigation, and {% live render %} embedded child views. This results in an Insecure Direct Object Reference (IDOR), where an authenticated user can view or interact with objects they are not authorized to access by loading the page directly, using SPA navigation, or composing it as an embedded child. This specifically affects object-scoped views; views without a custom get object() function are not impacted.Recommendations
Update djust to version 1.0.7.
Do not expose object-scoped views through HTTP GET,
url change, or live render paths until the update is applied.Exploit
Fix
IDOR
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Djust