Description
djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to version 1.0.7, djust's per-object authorization (`get_object` + `has_object_permission`, ADR-017) was enforced on the WebSocket mount and event paths but not on three other render entry points: (a) the initial HTTP GET render, (b) SPA `url_change` navigation, and (c) `{% live_render %}` embedded child views. An authenticated user could therefore view (and on some paths act on) an object they are not authorized for by loading the page directly, navigating to it via SPA url-change, or composing it as an embedded child — a classic IDOR / broken object-level access control on object-scoped views. This is fixed in djust 1.0.7. All render entry points now route through a shared `enforce_object_permission` chokepoint: HTTP GET returns 403, `url_change` emits a `permission_denied` frame and skips the render, and `{% live_render %}` (eager + lazy) refuses the embed. Views without a custom `get_object` are unaffected (no-op). No reliable workaround short of upgrading. Do not expose object-scoped views through the HTTP-GET / url_change / live_render paths until patched.
Published: 2026-09-16
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized Object Access
Action: Immediate Patch
AI Analysis

Impact

djust implemented a reactive rendering framework for Django but omitted per-object permission checks on three of its primary entry points—initial HTTP GET renders, SPA URL change navigation, and embedded child view rendering via the {% live_render %} tag. An authenticated user could exploit this oversight by directly requesting or navigating to an unauthorized object, thereby viewing its contents or, on certain paths, performing actions that the user should not be authorized for. The flaw maps to CWE-639 (Authorization Bypass Through User-Controlled Key) and CWE-862 (Missing Authorization).

Affected Systems

The vulnerable product is djust from djust-org. All releases prior to version 1.0.7 are affected; version 1.0.7 and later include a repair that forces all rendering flow through a centralized object‑permission checks.

Risk and Exploitability

The CVSS score of 7.1 indicates a high‑risk vulnerability, though the EPSS score is below 1 % suggesting low exploitation probability at present. Because the flaw requires an authenticated session, emphasis should be placed on preventing access to the vulnerable rendering endpoints. The vulnerability is not listed in CISA’s KEV catalog.

Generated by OpenCVE AI on September 17, 2026 at 21:10 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade djust to version 1.0.7 or later, which implements a centralized object‑permission enforcement.
  • Ensure that no legacy development or production deployment enables rendering through the initial HTTP GET, SPA URL change, or {% live_render %} paths until the patch is applied.
  • Review and harden any custom or third‑party views that render djust components to confirm they are not inadvertently exposed to unauthorized users.

Generated by OpenCVE AI on September 17, 2026 at 21:10 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-c7c5-5j6r-q957 djust has broken object-level access control (IDOR)
History

Thu, 17 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Djust-org
Djust-org djust
Vendors & Products Djust-org
Djust-org djust

Thu, 17 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 22:30:00 +0000

Type Values Removed Values Added
Description djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to version 1.0.7, djust's per-object authorization (`get_object` + `has_object_permission`, ADR-017) was enforced on the WebSocket mount and event paths but not on three other render entry points: (a) the initial HTTP GET render, (b) SPA `url_change` navigation, and (c) `{% live_render %}` embedded child views. An authenticated user could therefore view (and on some paths act on) an object they are not authorized for by loading the page directly, navigating to it via SPA url-change, or composing it as an embedded child — a classic IDOR / broken object-level access control on object-scoped views. This is fixed in djust 1.0.7. All render entry points now route through a shared `enforce_object_permission` chokepoint: HTTP GET returns 403, `url_change` emits a `permission_denied` frame and skips the render, and `{% live_render %}` (eager + lazy) refuses the embed. Views without a custom `get_object` are unaffected (no-op). No reliable workaround short of upgrading. Do not expose object-scoped views through the HTTP-GET / url_change / live_render paths until patched.
Title djust has broken object-level access control (IDOR)
Weaknesses CWE-639
CWE-862
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-17T14:40:10.907Z

Reserved: 2026-07-10T17:12:17.238Z

Link: CVE-2026-61596

cve-icon Vulnrichment

Updated: 2026-09-17T14:40:06.084Z

cve-icon NVD

Status : Deferred

Published: 2026-09-16T23:16:53.860

Modified: 2026-09-30T17:51:56.193

Link: CVE-2026-61596

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T21:15:14Z

Weaknesses
  • CWE-639

    Authorization Bypass Through User-Controlled Key

  • CWE-862

    Missing Authorization