16 Total advisories
16 Vulnerabilities
0 Malware

Dependency scanning

Check whether djust is in your codebase

Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.

Vulnerabilities

UNKNOWN
PyPI

GHSA-xjw9-38cr-6372

djust: A template binding inherits a context safety grant it never earned (XSS)

UNKNOWN
PyPI

GHSA-9395-2g46-rj3f

djust: Six template-layer defects emit attacker-controlled markup unescaped (XSS)

MEDIUM 6.3
PyPI

CVE-2026-61589

djust: WebSocket/runtime reconstructed request omits the client Host, causing host/subdomain TenantResolvers to misresolve the tenant on the live path

MEDIUM 6.5
PyPI

CVE-2026-61588

djust's Django model serialization has no sensitive-field denylist: password hashes, privilege flags, and PII on a public view attribute are sent to the client

CRITICAL 9.1
PyPI

CVE-2026-61594

djust has an authorization bypass on the WebSocket/SSE mount path

HIGH 8.1
PyPI

CVE-2026-61591

djust: Unsigned client state snapshot is restored as trusted view state (privilege escalation / state injection)

UNKNOWN
PyPI

CVE-2026-61599

djust has an unauthenticated arbitrary module import via the WebSocket/SSE view-mount path

HIGH 7.1
PyPI

CVE-2026-61596

djust has broken object-level access control (IDOR)

HIGH 7.4
PyPI

CVE-2026-61592

djust: SSE sessions are not bound to the authenticated user; the client-chosen session_id is the sole authorization capability (session hijack)

UNKNOWN
PyPI

CVE-2026-61597

djust is vulnerable to stored/reflected XSS via javascript: URLs in built-in component template tags

HIGH 8.1
PyPI

CVE-2026-61593

djust has Cross-Site Request Forgery on the Server-Sent-Events transport: a cross-origin page can drive a victim-authenticated SSE session

HIGH 7.7
PyPI

CVE-2026-61595

djust: Multi-tenant isolation fails open on the WebSocket/SSE path, disclosing other tenants' data

UNKNOWN
PyPI

CVE-2026-61598

djust: Client mass-assignment of arbitrary view attributes via the default dj-model update_model handler

HIGH 7.4
PyPI

CVE-2026-61590

djust's observability endpoints are network-exposed: the localhost gate is an opt-in middleware the docs omit, and the views enforce only DEBUG

HIGH 8.2
PyPI

CVE-2026-55571

djust authentication bypass: a login_required / on_mount LiveView mount redirect does not close the WebSocket, allowing an unauthenticated client to dispatch event-handler calls

HIGH 8.2
PyPI

CVE-2026-55571

djust authentication bypass: a login_required / on_mount LiveView mount redirect does not close the WebSocket, allowing an unauthenticated client to dispatch event-handler calls

Learn What is SAST?

Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →

Ready to move

Start Securing

Free, no credit card | First findings in minutes