Description
djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to version 1.0.7, the live (WebSocket) transport authorizes a mount via `check_view_auth`, not Django's `View.dispatch()` chain. As a result, standard Django authorization — `LoginRequiredMixin`, `PermissionRequiredMixin`, `UserPassesTestMixin`, `@method_decorator(login_required, name="dispatch")`, and custom `dispatch()` guards — and the djust admin extension's staff gate (applied only in the HTTP `as_view` wrapper) were enforced on the initial HTTP GET but silently bypassed over WebSocket, where all events and state flow. An anonymous or under-privileged client could open a WebSocket and mount such a view — including admin list/create/change/delete — and dispatch its handlers. This is fixed in djust 1.0.7. `check_view_auth` now honors the Django `AccessMixin` family on every transport; a new system check S004 fails loud at startup on auth patterns the runtime cannot safely replay (decorator/overridden-`dispatch` forms); and the admin base mixin declares `login_required = True` + an active-staff `check_permissions` gate. As a workaround, gate views using djust's `login_required` / `permission_required` / `check_permissions` attributes (honored on all transports) rather than HTTP-only mixins/decorators.
Published: 2026-09-16
Score: 9.1 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Privilege escalation via unauthorized access to protected admin views
Action: Immediate Patch
AI Analysis

Impact

The djust library performs the initial HTTP GET through Django’s standard authorization chain, but its WebSocket and Server‑Sent Events (SSE) transports bypass that chain. Prior to version 1.0.7, the mount was authorized only by a custom `check_view_auth` that did not honor Django’s access mixins or decorators. Consequently, an attacker who can reach the WebSocket mount path can open a socket, mount a protected view, and invoke any action exposed by that view, including administrative create, list, update or delete operations. The flaw is a classic missing authentication/authorization problem (CWE‑306 and CWE‑862) and allows an anonymous or minimally privileged client to exploit authenticated‑only functionality.

Affected Systems

This issue affects the djust project (djust-org:djust) in any release prior to 1.0.7. The vulnerability is present in all versions that use the old `check_view_auth` logic and is fixed in djust 1.0.7 and later. No additional vendor or product identifiers are available beyond the djust library itself.

Risk and Exploitability

The CVSS score of 9.1 indicates a high severity impact, while the EPSS score of less than 1 % suggests a low likelihood of active exploitation at present. The flaw is not listed in the CISA KEV catalog. The attack vector is remote. An attacker only needs the ability to establish a WebSocket connection to the mount path, and no authentication is required to bypass the checks. Because the vulnerability permits full access to privileged view actions, successful exploitation could lead to full administrative control over the Django application.

Generated by OpenCVE AI on September 17, 2026 at 21:11 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the djust library to version 1.0.7 or later to apply the patch that enforces Django authentication on all transports.
  • For legacy installations that cannot be upgraded immediately, protect affected views by applying djust’s own `login_required`, `permission_required`, or `check_permissions` attributes which are evaluated on every transport, effectively restoring the intended access control.
  • Add an explicit WebSocket authentication check (e.g., validate the session cookie or token before accepting the connection) to ensure that only authenticated users can open a socket to the mount path.
  • Limit exposure of the WebSocket/SSE mount path to trusted networks or enforce firewall rules that block unauthenticated access if possible.

Generated by OpenCVE AI on September 17, 2026 at 21:11 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-xhhm-f6hp-2qwj djust has an authorization bypass on the WebSocket/SSE mount path
History

Thu, 17 Sep 2026 21:15:00 +0000

Type Values Removed Values Added
First Time appeared Djust-org
Djust-org djust
Vendors & Products Djust-org
Djust-org djust

Thu, 17 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 22:15:00 +0000

Type Values Removed Values Added
Description djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to version 1.0.7, the live (WebSocket) transport authorizes a mount via `check_view_auth`, not Django's `View.dispatch()` chain. As a result, standard Django authorization — `LoginRequiredMixin`, `PermissionRequiredMixin`, `UserPassesTestMixin`, `@method_decorator(login_required, name="dispatch")`, and custom `dispatch()` guards — and the djust admin extension's staff gate (applied only in the HTTP `as_view` wrapper) were enforced on the initial HTTP GET but silently bypassed over WebSocket, where all events and state flow. An anonymous or under-privileged client could open a WebSocket and mount such a view — including admin list/create/change/delete — and dispatch its handlers. This is fixed in djust 1.0.7. `check_view_auth` now honors the Django `AccessMixin` family on every transport; a new system check S004 fails loud at startup on auth patterns the runtime cannot safely replay (decorator/overridden-`dispatch` forms); and the admin base mixin declares `login_required = True` + an active-staff `check_permissions` gate. As a workaround, gate views using djust's `login_required` / `permission_required` / `check_permissions` attributes (honored on all transports) rather than HTTP-only mixins/decorators.
Title djust has an authorization bypass on the WebSocket/SSE mount path
Weaknesses CWE-306
CWE-862
References
Metrics cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-17T14:39:07.324Z

Reserved: 2026-07-10T17:12:17.238Z

Link: CVE-2026-61594

cve-icon Vulnrichment

Updated: 2026-09-17T14:39:02.792Z

cve-icon NVD

Status : Deferred

Published: 2026-09-16T22:17:03.047

Modified: 2026-09-30T17:51:56.193

Link: CVE-2026-61594

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T21:15:14Z

Weaknesses
  • CWE-306

    Missing Authentication for Critical Function

  • CWE-862

    Missing Authorization