PT-2026-94124 · Pypi · Djust

CVE-2026-61599

·

Published

2026-09-16

·

Updated

2026-09-17

CVSS v4.0

8.8

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions djust versions prior to 1.0.7
Description djust allows an unauthenticated WebSocket or SSE client to trigger the import and execution of the top-level code of any importable Python module. This occurs because the live transport resolves the LiveView to mount using a client-supplied dotted path via the import () function before performing authentication or verifying if the object is a LiveView subclass. The LIVEVIEW ALLOWED MODULES allowlist is fail-open by default and uses loose startswith matching, enabling an attacker to send a mount, live redirect mount, or url change frame with a malicious view variable. This can lead to server-side execution of arbitrary import-time side effects, denial of service through import bombs, and module enumeration. The issue affects the handle mount function in python/djust/websocket.py, the ViewRuntime.dispatch mount and instantiate view functions in python/djust/runtime.py, and the SSE mount in python/djust/sse.py.
Recommendations Update djust to version 1.0.7. As a temporary mitigation, set LIVEVIEW ALLOWED MODULES to a narrow list of modules containing mountable LiveView classes.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-61599
GHSA-7PRP-2623-8G45

Affected Products

Djust