Impact
djust implemented a reactive rendering framework for Django but omitted per-object permission checks on three of its primary entry points—initial HTTP GET renders, SPA URL change navigation, and embedded child view rendering via the {% live_render %} tag. An authenticated user could exploit this oversight by directly requesting or navigating to an unauthorized object, thereby viewing its contents or, on certain paths, performing actions that the user should not be authorized for. The flaw maps to CWE-639 (Authorization Bypass Through User-Controlled Key) and CWE-862 (Missing Authorization).
Affected Systems
The vulnerable product is djust from djust-org. All releases prior to version 1.0.7 are affected; version 1.0.7 and later include a repair that forces all rendering flow through a centralized object‑permission checks.
Risk and Exploitability
The CVSS score of 7.1 indicates a high‑risk vulnerability, though the EPSS score is below 1 % suggesting low exploitation probability at present. Because the flaw requires an authenticated session, emphasis should be placed on preventing access to the vulnerable rendering endpoints. The vulnerability is not listed in CISA’s KEV catalog.
OpenCVE Enrichment
Github GHSA