VDB
Sign up
HIGH8.1

GHSA-c67v-vqrp-m5wj

djust: Unsigned client state snapshot is restored as trusted view state (privilege escalation / state injection)

Quick fix

GHSA-c67v-vqrp-m5wj — djust: upgrade to the fixed version with the command below.

pip install --upgrade 'djust>=1.0.7'

Details

### Impact For views that opt into state snapshots, the snapshot `state_json` embedded in the client page was restored on reconnect as **trusted** view state with no integrity check. A client could edit the unsigned `state_json` in their page and return it in the reconnect mount frame to **inject arbitrary view attributes** — e.g. flip `is_admin` to `True`, or change `account_id` / `balance` — escalating privilege or tampering with business state held in public view attributes (the normal djust pattern).

### Patches Fixed in **djust 1.0.7**. State snapshots are signed; unsigned or forged snapshots are rejected on the back-navigation restore path.

### Workarounds Do not enable state snapshots; do not hold authorization/ownership state in public view attributes.

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI/djust
Introduced in: 0Fixed in: 1.0.7
Fixpip install --upgrade 'djust>=1.0.7'

References