Impact
The vulnerability arises when server‑sent event (SSE) sessions are identified solely by a client‑supplied session_id that is not bound to the authenticated user. This flaw, classified under CWE‑384, CWE‑639, and CWE‑862, allows an attacker who learns or guesses a valid session_id to connect to the SSE endpoint and dispatch event handlers as if they were the victim. By hijacking the session, the attacker can execute code and actions with the victim’s credentials and state. The attack vector is inferred from the description, which indicates that learning or leaking a session_id suffices; thus network‑based observation or social‑engineering tactics can be employed.
Affected Systems
djust, a Rust‑powered Phoenix LiveView‑style reactive server‑side rendering framework for Django, is affected in all releases prior to version 1.0.7. Users running djust 1.0.6 or earlier are exposed to the flaw.
Risk and Exploitability
The CVSS score of 7.4 denotes a high‑risk vulnerability, while the EPSS score of less than 1% indicates a very low probability of exploitation at this time. The flaw is not listed in the CISA KEV catalog. Exploitation would require the attacker to obtain a legitimate session_id—through traffic analysis, social engineering, or brute force—which would then allow the attacker to hijack the SSE session over the network and issue event handlers, effectively executing code under the victim’s identity.
OpenCVE Enrichment
Github GHSA