Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-c67v-vqrp-m5wj | djust: Unsigned client state snapshot is restored as trusted view state (privilege escalation / state injection) |
Wed, 16 Sep 2026 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to version 1.0.7, for views that opt into state snapshots, the snapshot `state_json` embedded in the client page was restored on reconnect as trusted view state with no integrity check. A client could edit the unsigned `state_json` in their page and return it in the reconnect mount frame to inject arbitrary view attributes — e.g. flip `is_admin` to `True`, or change `account_id` / `balance` — escalating privilege or tampering with business state held in public view attributes (the normal djust pattern). This issue is fixed in djust 1.0.7. State snapshots are signed; unsigned or forged snapshots are rejected on the back-navigation restore path. As a workaround, do not enable state snapshots; do not hold authorization/ownership state in public view attributes. | |
| Title | djust: Unsigned client state snapshot is restored as trusted view state (privilege escalation / state injection) | |
| Weaknesses | CWE-345 CWE-915 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-09-16T21:57:26.957Z
Reserved: 2026-07-10T17:12:17.237Z
Link: CVE-2026-61591
No data.
Status : Received
Published: 2026-09-16T22:17:02.763
Modified: 2026-09-16T22:17:02.763
Link: CVE-2026-61591
No data.
OpenCVE Enrichment
No data.
Github GHSA