Description
djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to version 1.0.7, many djust built-in component template tags (`djust.components.templatetags.*`) render a developer/user-supplied URL into an `href` / `action` attribute, HTML-escaping it with `conditional_escape` but never validating the URL scheme. HTML escaping prevents attribute breakout but does not neutralize a `javascript:` URI (which needs no escapable characters), so a URL value of `javascript:alert(document.cookie)` lands verbatim in `<a href="javascript:alert(document.cookie)">` and executes in the victim's session on click. Version 1.0.7 contains a fix. As a workaround, do not pass user-controllable URLs to the affected built-in component tags; pre-validate URL schemes in application code before binding them to component arguments.
Published: 2026-09-16
Score: 5.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Stored or reflected XSS enabling arbitrary JavaScript execution in the victim’s browser
Action: Apply Patch
AI Analysis

Impact

djust renders a developer or user supplied URL into an anchor or form attribute using conditional escaping, but does not validate the URL scheme. The escape mitigates attribute breakout but simply a javascript: URI bypasses the reach of escaping, allowing the URI to be inserted verbatim into an href or action attribute. When the victim clicks the link, the browser interprets the URI as a script and runs it in the context of the application, providing an attacker with the ability to read session cookies, deface pages, or launch further attacks. The weakness is a classic example of client‑side injection (CWE‑79).

Affected Systems

This flaw appears in the djust framework for Django, in all installed versions of djust-org:djust released before v1.0.7. The fix was introduced in release 1.0.7 and later. No other vendors or products are mentioned as affected.

Risk and Exploitability

The severity of the flaw is assessed with a CVSS score of 5.1, indicating a medium likelihood of impact. The EPSS score is reported as less than 1%, suggesting a low probability of actual exploitation at present. The vulnerability is not listed in CISA’s KEV catalog, indicating no known active exploit in the wild. Attackers could deliver the malicious URL through the built‑in component tags by supplying user‑controlled input; the flaw can be both reflected and stored, depending on how the application uses the tags. An attacker would need to place the malicious URL in an instance of the template tag’s arguments and then lure a user to click the resulting link. Fairly simple in practice, this requires only that the attacker control the component argument value, making the vector relatively straightforward for applications that expose these tags to arbitrary input.

Generated by OpenCVE AI on September 17, 2026 at 21:12 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade djust to version 1.0.7 or later to eliminate the vulnerability.
  • If upgrading is not immediately possible, avoid passing any user‑controlled URLs to the affected component template tags.
  • Implement server‑side validation or whitelisting of URL schemes (e.g., only allow http and https) before binding the value to the component arguments.

Generated by OpenCVE AI on September 17, 2026 at 21:12 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-4mf4-73j6-mvrw djust is vulnerable to stored/reflected XSS via javascript: URLs in built-in component template tags
History

Thu, 17 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Djust-org
Djust-org djust
Vendors & Products Djust-org
Djust-org djust

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 22:00:00 +0000

Type Values Removed Values Added
Description djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to version 1.0.7, many djust built-in component template tags (`djust.components.templatetags.*`) render a developer/user-supplied URL into an `href` / `action` attribute, HTML-escaping it with `conditional_escape` but never validating the URL scheme. HTML escaping prevents attribute breakout but does not neutralize a `javascript:` URI (which needs no escapable characters), so a URL value of `javascript:alert(document.cookie)` lands verbatim in `<a href="javascript:alert(document.cookie)">` and executes in the victim's session on click. Version 1.0.7 contains a fix. As a workaround, do not pass user-controllable URLs to the affected built-in component tags; pre-validate URL schemes in application code before binding them to component arguments.
Title djust is vulnerable to stored/reflected XSS via javascript: URLs in built-in component template tags
Weaknesses CWE-79
References
Metrics cvssV4_0

{'score': 5.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-17T15:06:13.521Z

Reserved: 2026-07-10T17:12:17.238Z

Link: CVE-2026-61597

cve-icon Vulnrichment

Updated: 2026-09-17T15:06:10.714Z

cve-icon NVD

Status : Deferred

Published: 2026-09-16T22:17:03.187

Modified: 2026-09-30T17:51:56.193

Link: CVE-2026-61597

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T21:15:14Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')