Description
djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to version 1.0.7, when a Django `Model` instance is assigned to a public view attribute, djust serialized it to the client with no sensitive-field denylist — sending fields such as `password` (the hash), privilege flags (e.g. `is_staff` / `is_superuser`), tokens, and other PII to the browser. Because exposing model objects to templates is a normal djust pattern, this could leak credentials/PII without the developer realizing the full object crossed the wire. This is fixed in djust 1.0.7. Model serialization applies a secure-by-default sensitive-field denylist (password/hash/token/secret-style fields and known privilege flags are withheld) with an identity-subset fallback. As a workaround, keep `Model` instances on `_private` attributes and expose only the specific fields needed, until patched.
Published: 2026-09-16
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Sensitive data exposure
Action: Patch immediately
AI Analysis

Impact

djust, a Django extension, serializes entire Django Model instances to the client when assigned to a public view attribute. Because serialization lacked any denylist, sensitive fields such as password hashes, privilege flags, tokens and other personally identifiable information were transmitted to the browser. The flaw allows an attacker who can trigger such a view to gain knowledge of authentication credentials, elevate privileges, and expose private data, thereby compromising confidentiality and potentially integrity of user accounts.

Affected Systems

The vulnerability affects the djust library, specifically versions released before 1.0.7. Developers using djust in Django projects that expose Model instances in public view attributes are impacted. Any environment running djust 1.0.6 or earlier, regardless of Django version, is susceptible until patched to the fixed release.

Risk and Exploitability

The CVSS score of 6.5 indicates a medium severity risk and the EPSS score of less than 1% suggests a low likelihood of exploitation in the wild. The flaw is not listed in the CISA KEV catalog. Attackers can exploit the vulnerability by requesting any web page that renders a public view attribute containing a Model instance. As the serialization occurs server‑side and the data is sent to the client without filtering, the attack can be carried out remotely through normal HTTP requests to the affected view. The absence of a denylist means the entire object payload is exposed, making the attack highly effective if the view is publicly accessible.

Generated by OpenCVE AI on September 18, 2026 at 00:31 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade djust to version 1.0.7 or later to enable the secure-by-default denylist for model serialization.
  • Modify all public view attributes that assign Django Model instances to use private (underscore‑prefixed) attributes or explicitly expose only the fields required by the template.
  • As a temporary workaround, Model instances in private attributes and expose only the specific fields needed until the vendor releases a patch in djust 1.0.7.

Generated by OpenCVE AI on September 18, 2026 at 00:31 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-pvg3-6q9j-mj3x djust's Django model serialization has no sensitive-field denylist: password hashes, privilege flags, and PII on a public view attribute are sent to the client
History

Sat, 19 Sep 2026 02:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 01:00:00 +0000

Type Values Removed Values Added
First Time appeared Djust-org
Djust-org djust
Vendors & Products Djust-org
Djust-org djust

Wed, 16 Sep 2026 22:30:00 +0000

Type Values Removed Values Added
Description djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to version 1.0.7, when a Django `Model` instance is assigned to a public view attribute, djust serialized it to the client with no sensitive-field denylist — sending fields such as `password` (the hash), privilege flags (e.g. `is_staff` / `is_superuser`), tokens, and other PII to the browser. Because exposing model objects to templates is a normal djust pattern, this could leak credentials/PII without the developer realizing the full object crossed the wire. This is fixed in djust 1.0.7. Model serialization applies a secure-by-default sensitive-field denylist (password/hash/token/secret-style fields and known privilege flags are withheld) with an identity-subset fallback. As a workaround, keep `Model` instances on `_private` attributes and expose only the specific fields needed, until patched.
Title djust's Django model serialization has no sensitive-field denylist: password hashes, privilege flags, and PII on a public view attribute are sent to the client
Weaknesses CWE-200
CWE-359
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-19T02:06:36.974Z

Reserved: 2026-07-10T17:12:17.237Z

Link: CVE-2026-61588

cve-icon Vulnrichment

Updated: 2026-09-19T02:06:30.842Z

cve-icon NVD

Status : Deferred

Published: 2026-09-16T23:16:52.630

Modified: 2026-09-24T21:25:27.050

Link: CVE-2026-61588

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T00:45:16Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor

  • CWE-359

    Exposure of Private Personal Information to an Unauthorized Actor