OFFLINE
Awaiting data
Security intelligence
CriticalCritical vulnerability

CVE-2026-61594: djust has an authorization bypass on the WebSocket/SSE mount path

GitHub Advisories · officialPublished Sep 16, 2026Risk 50/100

### Impact The live (WebSocket) transport authorizes a mount via `check_view_auth`, not Django's `View.dispatch()` chain. As a result, standard Django authorization — `LoginRequiredMixin`, `PermissionRequiredMixin`, `UserPassesTestMixin`, `@method_decorator(login_required, name="dispatch")`, and custom `dispatch()` guards — **and** the djust admin extension's staff gate (applied only in the HTTP `as_view` wrapper) were enforced on the initial HTTP GET but **silently bypassed over WebSocket**, where all events and state flow. An anonymous or under-privileged client could open a WebSocket and mount such a view — including admin list/create/change/delete — and dispatch its handlers. ### Patches Fixed in **djust 1.0.7**. `check_view_auth` now honors the Django `AccessMixin` family on every transport; a new system check **S004** fails loud at startup on auth patterns the runtime cannot safely replay (decorator/overridden-`dispatch` forms); and the admin base mixin declares `login_required = True` + an active-staff `check_permissions` gate. ### Workarounds Gate views using djust's `login_required` / `permission_required` / `check_permissions` attributes (honored on all transports) rather than HTTP-only mixins/decorators.

Upgrade affected packages to a patched version: djust 1.0.7.

Vendor
Not specified
Product
djust
Exploitation
none known
Evidence
official
CVSS
9.1

This record is attributed to GitHub Advisories. Exploitation status and remediation guidance are kept separate from the vulnerability's technical severity.

Open primary source