16 Total advisories
16 Vulnerabilities
0 Malware
Dependency scanning
Check whether djust is in your codebase
Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.
Vulnerabilities
UNKNOWN
GHSA-xjw9-38cr-6372
djust: A template binding inherits a context safety grant it never earned (XSS)
UNKNOWN
GHSA-9395-2g46-rj3f
djust: Six template-layer defects emit attacker-controlled markup unescaped (XSS)
MEDIUM 6.3
CVE-2026-61589
djust: WebSocket/runtime reconstructed request omits the client Host, causing host/subdomain TenantResolvers to misresolve the tenant on the live path
MEDIUM 6.5
CVE-2026-61588
djust's Django model serialization has no sensitive-field denylist: password hashes, privilege flags, and PII on a public view attribute are sent to the client
CRITICAL 9.1
CVE-2026-61594
djust has an authorization bypass on the WebSocket/SSE mount path
HIGH 8.1
CVE-2026-61591
djust: Unsigned client state snapshot is restored as trusted view state (privilege escalation / state injection)
UNKNOWN
CVE-2026-61599
djust has an unauthenticated arbitrary module import via the WebSocket/SSE view-mount path
HIGH 7.1
CVE-2026-61596
djust has broken object-level access control (IDOR)
HIGH 7.4
CVE-2026-61592
djust: SSE sessions are not bound to the authenticated user; the client-chosen session_id is the sole authorization capability (session hijack)
UNKNOWN
CVE-2026-61597
djust is vulnerable to stored/reflected XSS via javascript: URLs in built-in component template tags
HIGH 8.1
CVE-2026-61593
djust has Cross-Site Request Forgery on the Server-Sent-Events transport: a cross-origin page can drive a victim-authenticated SSE session
HIGH 7.7
CVE-2026-61595
djust: Multi-tenant isolation fails open on the WebSocket/SSE path, disclosing other tenants' data
UNKNOWN
CVE-2026-61598
djust: Client mass-assignment of arbitrary view attributes via the default dj-model update_model handler
HIGH 7.4
CVE-2026-61590
djust's observability endpoints are network-exposed: the localhost gate is an opt-in middleware the docs omit, and the views enforce only DEBUG
HIGH 8.2
CVE-2026-55571
djust authentication bypass: a login_required / on_mount LiveView mount redirect does not close the WebSocket, allowing an unauthenticated client to dispatch event-handler calls
HIGH 8.2
CVE-2026-55571
djust authentication bypass: a login_required / on_mount LiveView mount redirect does not close the WebSocket, allowing an unauthenticated client to dispatch event-handler calls
Browse more PyPI advisories
Learn What is SAST?
Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →
Ready to move
Start Securing
Free, no credit card | First findings in minutes