GHSA-c67v-vqrp-m5wj
djust: Unsigned client state snapshot is restored as trusted view state (privilege escalation / state injection)
Quick fix
GHSA-c67v-vqrp-m5wj — djust: upgrade to the fixed version with the command below.
pip install --upgrade 'djust>=1.0.7'Details
### Impact For views that opt into state snapshots, the snapshot `state_json` embedded in the client page was restored on reconnect as **trusted** view state with no integrity check. A client could edit the unsigned `state_json` in their page and return it in the reconnect mount frame to **inject arbitrary view attributes** — e.g. flip `is_admin` to `True`, or change `account_id` / `balance` — escalating privilege or tampering with business state held in public view attributes (the normal djust pattern).
### Patches Fixed in **djust 1.0.7**. State snapshots are signed; unsigned or forged snapshots are rejected on the back-navigation restore path.
### Workarounds Do not enable state snapshots; do not hold authorization/ownership state in public view attributes.
Are you affected?
Enter the version of the package you're using.