CVE-2026-61591: djust: Unsigned client state snapshot is restored as trusted view state (privilege escalation / state injection)
### Impact For views that opt into state snapshots, the snapshot `state_json` embedded in the client page was restored on reconnect as **trusted** view state with no integrity check. A client could edit the unsigned `state_json` in their page and return it in the reconnect mount frame to **inject arbitrary view attributes** — e.g. flip `is_admin` to `True`, or change `account_id` / `balance` — escalating privilege or tampering with business state held in public view attributes (the normal djust pattern). ### Patches Fixed in **djust 1.0.7**. State snapshots are signed; unsigned or forged snapshots are rejected on the back-navigation restore path. ### Workarounds Do not enable state snapshots; do not hold authorization/ownership state in public view attributes.
Recommended action
Recommended action
Upgrade affected packages to a patched version: djust 1.0.7.
Technical details
- Vendor
- Not specified
- Product
- djust
- Exploitation
- none known
- Evidence
- official
Evidence and sources
This record is attributed to GitHub Advisories. Exploitation status and remediation guidance are kept separate from the vulnerability's technical severity.
Open primary source