Impact
A client can supply a dotted path for the LiveView module via a WebSocket or SSE mount frame, and the framework imports that module before checking that it is a LiveView subclass or validating the user. The import executes the module’s top‑level code, giving the attacker the ability to run arbitrary Python code on the server. This vulnerability is a classic arbitrary code execution flaw identified as CWE‑470.
Affected Systems
The djust framework from djust-org is affected in all releases older than version 1.0.7. The security advisory indicates that the issue was resolved in release 1.0.7.
Risk and Exploitability
The CVSS score of 8.8 highlights a high severity vulnerability, but the EPSS score is below 1%, suggesting it is currently rarely exploited. The vulnerability is not listed in the CISA KEV catalog. Attackers need only reach the unprotected WebSocket endpoint to send a specially crafted mount frame; authentication checks run only after the import, so no credentials are required. Once the frame is processed, the server executes the attacker‑supplied module, potentially giving full code‑execution privileges.
OpenCVE Enrichment
Github GHSA