HIGH 7.1 GitHub
CVE-2026-61596
djust has broken object-level access control (IDOR)
### Impact
djust's per-object authorization (`get_object` + `has_object_permission`, ADR-017) was enforced on the WebSocket **mount** and **event** paths but **not** on three other render entry points: (a) the initial **HTTP GET** render, (b) **SPA `url_change`** navigation, and (c) `{% live_render %}` **embedded child** views. An authenticated user could therefore view (and on some paths act on) an object they are not authorized for by loading the page directly, navigating to it via SPA url-cha
Affected Products
- pip/djust < 1.0.7
References
- https://github.com/advisories/GHSA-c7c5-5j6r-q957
- https://github.com/djust-org/djust/security/advisories/GHSA-c7c5-5j6r-q957
- https://github.com/djust-org/djust/releases/tag/v1.0.7
- https://github.com/advisories/GHSA-c7c5-5j6r-q957
This high severity vulnerability with a CVSS score of 7.1 was published on 2026-09-16 via GitHub. Affected: pip/djust < 1.0.7.
vulnfeed aggregates 14597 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.