Description
djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to version 1.0.7, the SSE client→server POST endpoints are `@csrf_exempt` and the SSE GET stream endpoint had no Origin check, so a cross-origin page could drive a victim-cookie-authenticated SSE session: force the victim's browser to GET the stream URL (which creates and mounts a LiveView as the victim) and POST to the message endpoint with `credentials: include` to fire state-changing event handlers as the victim. The URL `session_id` is client-chosen (validated only for UUID *format*), so it is not a CSRF token, and a JSON body sent as `text/plain` is a CORS simple request with no preflight. The issue is fixed in 1.0.7. All three SSE endpoints validate the request `Origin` against `ALLOWED_HOSTS` (mirroring the WebSocket CSWSH defense) and reject cross-origin requests with 403; the POST endpoints additionally require `Content-Type: application/json` (415 otherwise), closing the `text/plain` simple-request bypass. As a workaround, disable the SSE transport, or front it with a proxy that enforces an Origin allowlist.
Published: 2026-09-16
Score: 8.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Cross‑Site Request Forgery that enables authenticated state‑changing actions
Action: Immediate Patch
AI Analysis

Impact

The vulnerability arises because the Server‑Sent‑Events client‑to‑server POST endpoints are exempt from CSRF protection and the stream GET endpoint lacks origin validation. A cross‑origin page can therefore instruct a victim’s authenticated browser to connect to the SSE stream, causing a LiveView instance to be created under the victim’s credentials, and then POST a text/plain payload to the message endpoint. Because the payload is a simple CORS request with no preflight, the attacker can trigger state‑changing event handlers without the victim’s consent. The flaw permits authenticated clients to perform arbitrary state changes on behalf of the victim, undermining data confidentiality, integrity and potentially exposing privileged actions.

Affected Systems

The affected product is djust, a Django framework with Rust‑powered SSE transport, distributed by djust‑org. All releases prior to version 1.0.7 contain the flaw. The vulnerability was addressed in the 1.0.7 release and later versions.

Risk and Exploitability

The CVSS score of 8.1 classifies this issue as High, and the EPSS score of less than 1% indicates a low probability of exploitation at any given time. Because the flaw relies on a victim visiting a malicious cross‑origin site while logged into djust, an attacker does not need elevated privileges or additional credentials. The defect is not listed in CISA’s KEV catalog. In practice, the vulnerability can be abused to cause unauthorized state changes in djust applications, so administrators should assess whether the SSE transport is essential and apply the patch promptly.

Generated by OpenCVE AI on September 18, 2026 at 01:18 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the official patch by upgrading djust to version 1.0.7 or later.
  • If upgrading is not immediately possible, disable the SSE transport entirely to eliminate the vulnerable endpoints.
  • Alternatively, place a reverse proxy that validates the Origin header against an allowlist before forwarding SSE requests.

Generated by OpenCVE AI on September 18, 2026 at 01:18 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-pg97-jvmf-qfvc djust has Cross-Site Request Forgery on the Server-Sent-Events transport: a cross-origin page can drive a victim-authenticated SSE session
History

Fri, 18 Sep 2026 08:15:00 +0000

Type Values Removed Values Added
First Time appeared Djust-org
Djust-org djust
Vendors & Products Djust-org
Djust-org djust

Wed, 16 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 16:00:00 +0000

Type Values Removed Values Added
Description djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to version 1.0.7, the SSE client→server POST endpoints are `@csrf_exempt` and the SSE GET stream endpoint had no Origin check, so a cross-origin page could drive a victim-cookie-authenticated SSE session: force the victim's browser to GET the stream URL (which creates and mounts a LiveView as the victim) and POST to the message endpoint with `credentials: include` to fire state-changing event handlers as the victim. The URL `session_id` is client-chosen (validated only for UUID *format*), so it is not a CSRF token, and a JSON body sent as `text/plain` is a CORS simple request with no preflight. The issue is fixed in 1.0.7. All three SSE endpoints validate the request `Origin` against `ALLOWED_HOSTS` (mirroring the WebSocket CSWSH defense) and reject cross-origin requests with 403; the POST endpoints additionally require `Content-Type: application/json` (415 otherwise), closing the `text/plain` simple-request bypass. As a workaround, disable the SSE transport, or front it with a proxy that enforces an Origin allowlist.
Title djust has Cross-Site Request Forgery on the Server-Sent-Events transport: a cross-origin page can drive a victim-authenticated SSE session
Weaknesses CWE-352
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-16T18:32:21.613Z

Reserved: 2026-07-10T17:12:17.238Z

Link: CVE-2026-61593

cve-icon Vulnrichment

Updated: 2026-09-16T18:32:16.563Z

cve-icon NVD

Status : Deferred

Published: 2026-09-16T16:17:13.943

Modified: 2026-09-30T17:51:56.193

Link: CVE-2026-61593

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T08:00:06Z

Weaknesses
  • CWE-352

    Cross-Site Request Forgery (CSRF)