Description
djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to version 1.0.7, for views that opt into state snapshots, the snapshot `state_json` embedded in the client page was restored on reconnect as trusted view state with no integrity check. A client could edit the unsigned `state_json` in their page and return it in the reconnect mount frame to inject arbitrary view attributes — e.g. flip `is_admin` to `True`, or change `account_id` / `balance` — escalating privilege or tampering with business state held in public view attributes (the normal djust pattern). This issue is fixed in djust 1.0.7. State snapshots are signed; unsigned or forged snapshots are rejected on the back-navigation restore path. As a workaround, do not enable state snapshots; do not hold authorization/ownership state in public view attributes.
Published: 2026-09-16
Score: 8.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Privilege Escalation via State Injection
Action: Apply Patch
AI Analysis

Impact

An unsigned client‑side snapshot of view state is restored without an integrity check when a user reconnects. A malicious client can modify the snapshot JSON and return it, causing arbitrary view attributes to be set, such as toggling an admin flag or changing account identifiers and balances. This allows an attacker to gain higher privileges or tamper with business data. The weakness is rooted in the lack of signed snapshots and the mis‑treatment of public view attributes, leading to a classic state injection problem.

Affected Systems

The vulnerability affects djust deployments running versions earlier than 1.0.7 from the djust-org djust product. All releases before 1.0.7 that enable state snapshots are susceptible; the fix begins at 1.0.7 and later.

Risk and Exploitability

With a CVSS score of 8.1 the potential impact is high. The EPSS score of less than 1% suggests that exploitation is currently unlikely, and the flaw is not listed in the CISA KEV catalog. The attack vector requires only client‑side manipulation of a page snapshot, meaning an attacker can perform the attack from any browser session that can connect to the vulnerable djust instance. The risk is therefore moderate to high, emphasizing the importance of applying the available patch to eliminate the privilege escalation path.

Generated by OpenCVE AI on September 17, 2026 at 22:21 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the djust package to version 1.0.7 or later to enable signed snapshots and reject unsigned or forged state data.
  • If an upgrade cannot be performed immediately, configure the application to disable state snapshots entirely, preventing the vulnerable restore path from being exercised.
  • Avoid storing authorization or ownership data in public view attributes; ensure such sensitive attributes are always validated server‑side regardless of snapshot state.
  • Confirm that all new deploys have signed snapshots enabled; if using snapshots, verify the signature before restoring state.

Generated by OpenCVE AI on September 17, 2026 at 22:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-c67v-vqrp-m5wj djust: Unsigned client state snapshot is restored as trusted view state (privilege escalation / state injection)
History

Thu, 17 Sep 2026 23:30:00 +0000

Type Values Removed Values Added
First Time appeared Djust-org
Djust-org djust
Vendors & Products Djust-org
Djust-org djust

Thu, 17 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 22:15:00 +0000

Type Values Removed Values Added
Description djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to version 1.0.7, for views that opt into state snapshots, the snapshot `state_json` embedded in the client page was restored on reconnect as trusted view state with no integrity check. A client could edit the unsigned `state_json` in their page and return it in the reconnect mount frame to inject arbitrary view attributes — e.g. flip `is_admin` to `True`, or change `account_id` / `balance` — escalating privilege or tampering with business state held in public view attributes (the normal djust pattern). This issue is fixed in djust 1.0.7. State snapshots are signed; unsigned or forged snapshots are rejected on the back-navigation restore path. As a workaround, do not enable state snapshots; do not hold authorization/ownership state in public view attributes.
Title djust: Unsigned client state snapshot is restored as trusted view state (privilege escalation / state injection)
Weaknesses CWE-345
CWE-915
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-17T13:22:26.195Z

Reserved: 2026-07-10T17:12:17.237Z

Link: CVE-2026-61591

cve-icon Vulnrichment

Updated: 2026-09-17T13:22:17.998Z

cve-icon NVD

Status : Deferred

Published: 2026-09-16T22:17:02.763

Modified: 2026-09-30T17:51:56.193

Link: CVE-2026-61591

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T23:15:15Z

Weaknesses
  • CWE-345

    Insufficient Verification of Data Authenticity

  • CWE-915

    Improperly Controlled Modification of Dynamically-Determined Object Attributes