Impact
The djust library performs the initial HTTP GET through Django’s standard authorization chain, but its WebSocket and Server‑Sent Events (SSE) transports bypass that chain. Prior to version 1.0.7, the mount was authorized only by a custom `check_view_auth` that did not honor Django’s access mixins or decorators. Consequently, an attacker who can reach the WebSocket mount path can open a socket, mount a protected view, and invoke any action exposed by that view, including administrative create, list, update or delete operations. The flaw is a classic missing authentication/authorization problem (CWE‑306 and CWE‑862) and allows an anonymous or minimally privileged client to exploit authenticated‑only functionality.
Affected Systems
This issue affects the djust project (djust-org:djust) in any release prior to 1.0.7. The vulnerability is present in all versions that use the old `check_view_auth` logic and is fixed in djust 1.0.7 and later. No additional vendor or product identifiers are available beyond the djust library itself.
Risk and Exploitability
The CVSS score of 9.1 indicates a high severity impact, while the EPSS score of less than 1 % suggests a low likelihood of active exploitation at present. The flaw is not listed in the CISA KEV catalog. The attack vector is remote. An attacker only needs the ability to establish a WebSocket connection to the mount path, and no authentication is required to bypass the checks. Because the vulnerability permits full access to privileged view actions, successful exploitation could lead to full administrative control over the Django application.
OpenCVE Enrichment
Github GHSA