PT-2026-94124 · Pypi · Djust
CVE-2026-61599
·
Published
2026-09-16
·
Updated
2026-09-17
CVSS v4.0
8.8
High
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
djust versions prior to 1.0.7
Description
djust allows an unauthenticated WebSocket or SSE client to trigger the import and execution of the top-level code of any importable Python module. This occurs because the live transport resolves the LiveView to mount using a client-supplied dotted path via the
import () function before performing authentication or verifying if the object is a LiveView subclass. The LIVEVIEW ALLOWED MODULES allowlist is fail-open by default and uses loose startswith matching, enabling an attacker to send a mount, live redirect mount, or url change frame with a malicious view variable. This can lead to server-side execution of arbitrary import-time side effects, denial of service through import bombs, and module enumeration. The issue affects the handle mount function in python/djust/websocket.py, the ViewRuntime.dispatch mount and instantiate view functions in python/djust/runtime.py, and the SSE mount in python/djust/sse.py.Recommendations
Update djust to version 1.0.7.
As a temporary mitigation, set
LIVEVIEW ALLOWED MODULES to a narrow list of modules containing mountable LiveView classes.Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Djust