Impact
Observability endpoints in djust expose session and view state and provide a remote evaluation surface named eval_handler. The default configuration only enforces the DEBUG flag, while the localhost restriction is implemented by an optional middleware that is omitted from the documentation. When DEBUG is enabled and the middleware is absent, any external client can access these endpoints and invoke handlers remotely, potentially executing arbitrary code. This flaw corresponds to missing authentication for an API (CWE‑306) and improper permission management (CWE‑668).
Affected Systems
djust, released by djust‑org, is vulnerable in all versions before 1.0.7. The patch introduced in version 1.0.7 removes the dependency on the opt‑in middleware, enforces localhost checks within the view logic, and blocks eval_handler unless the request originates locally.
Risk and Exploitability
The vulnerability carries a CVSS score of 7.4, indicating high severity. The EPSS score is below 1 %, suggesting that exploitation is uncommon but still possible. The flaw is not yet listed in CISA’s KEV catalog. An attacker who can reach the observability endpoints from an untrusted network can read application state and invoke eval_handler. If the evaluated handler executes code, this results in remote code execution. Because the endpoints are only protected when DEBUG is disabled or the optional middleware is installed, a misconfigured production deployment is the most realistic attack scenario. The risk is therefore moderate to high, especially for services that expose these endpoints to the public internet.
OpenCVE Enrichment
Github GHSA