Impact
The vulnerability arises because the Server‑Sent‑Events client‑to‑server POST endpoints are exempt from CSRF protection and the stream GET endpoint lacks origin validation. A cross‑origin page can therefore instruct a victim’s authenticated browser to connect to the SSE stream, causing a LiveView instance to be created under the victim’s credentials, and then POST a text/plain payload to the message endpoint. Because the payload is a simple CORS request with no preflight, the attacker can trigger state‑changing event handlers without the victim’s consent. The flaw permits authenticated clients to perform arbitrary state changes on behalf of the victim, undermining data confidentiality, integrity and potentially exposing privileged actions.
Affected Systems
The affected product is djust, a Django framework with Rust‑powered SSE transport, distributed by djust‑org. All releases prior to version 1.0.7 contain the flaw. The vulnerability was addressed in the 1.0.7 release and later versions.
Risk and Exploitability
The CVSS score of 8.1 classifies this issue as High, and the EPSS score of less than 1% indicates a low probability of exploitation at any given time. Because the flaw relies on a victim visiting a malicious cross‑origin site while logged into djust, an attacker does not need elevated privileges or additional credentials. The defect is not listed in CISA’s KEV catalog. In practice, the vulnerability can be abused to cause unauthorized state changes in djust applications, so administrators should assess whether the SSE transport is essential and apply the patch promptly.
OpenCVE Enrichment
Github GHSA