๐Ÿ” CVE Alert

CVE-2026-61594

CRITICAL 9.1

djust has an authorization bypass on the WebSocket/SSE mount path

CVSS Score
9.1
EPSS Score
0.0%
EPSS Percentile
0th

djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to version 1.0.7, the live (WebSocket) transport authorizes a mount via `check_view_auth`, not Django's `View.dispatch()` chain. As a result, standard Django authorization โ€” `LoginRequiredMixin`, `PermissionRequiredMixin`, `UserPassesTestMixin`, `@method_decorator(login_required, name="dispatch")`, and custom `dispatch()` guards โ€” and the djust admin extension's staff gate (applied only in the HTTP `as_view` wrapper) were enforced on the initial HTTP GET but silently bypassed over WebSocket, where all events and state flow. An anonymous or under-privileged client could open a WebSocket and mount such a view โ€” including admin list/create/change/delete โ€” and dispatch its handlers. This is fixed in djust 1.0.7. `check_view_auth` now honors the Django `AccessMixin` family on every transport; a new system check S004 fails loud at startup on auth patterns the runtime cannot safely replay (decorator/overridden-`dispatch` forms); and the admin base mixin declares `login_required = True` + an active-staff `check_permissions` gate. As a workaround, gate views using djust's `login_required` / `permission_required` / `check_permissions` attributes (honored on all transports) rather than HTTP-only mixins/decorators.

CWE CWE-306 CWE-862
Vendor djust-org
Product djust
Published Sep 16, 2026
Stay Ahead of the Next One

Get instant alerts for djust-org djust

Be the first to know when new critical vulnerabilities affecting djust-org djust are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
None

Affected Versions

djust-org / djust
< 1.0.7

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/djust-org/djust/security/advisories/GHSA-xhhm-f6hp-2qwj github.com: https://github.com/djust-org/djust/releases/tag/v1.0.7