Impact
Prior to version 1.0.7 djust, a Python framework for reactive server‑side rendering, stored the current tenant in a thread‑local variable set only by HTTP middleware. When a WebSocket or Server‑Sent Events connection was opened, the tenant value was None, causing the tenant‑aware QuerySet manager to operate in an unrestricted mode and return unfiltered data. This flaw allows any user who can open a WebSocket/SSE link to read rows belonging to all tenants, effectively bypassing tenant isolation and exposing sensitive data across the entire application.
Affected Systems
djust-org’s djust library, any release prior to 1.0.7. The vulnerability is fixed in version 1.0.7 and later; any Django project using the library with WebSocket or SSE endpoints prior to that upgrade is affected.
Risk and Exploitability
The CVSS score of 7.7 indicates high severity, while the EPSS score of less than 1% suggests a low likelihood of exploitation currently, and the issue is not listed in CISA KEV. Exploitation requires the attacker to open a WebSocket or SSE connection to the application; because the tenant context is missing, the ORM returns all rows, disclosing every tenant’s data. No workaround exists for the live (WebSocket/SSE) path. Maintaining STRICT_MODE and enabling the system check S006 helps detect mis‑configurations and mitigate risk.
OpenCVE Enrichment
Github GHSA