GHSA-f795-p5jw-j6g2
djust: SSE sessions are not bound to the authenticated user; the client-chosen session_id is the sole authorization capability (session hijack)
Quick fix
GHSA-f795-p5jw-j6g2 — djust: upgrade to the fixed version with the command below.
pip install --upgrade 'djust>=1.0.7'Details
### Impact SSE sessions were keyed solely by a **client-chosen** `session_id` with no binding to the authenticated user — a control the WebSocket transport has but that was dropped on SSE. An attacker who learns (or a victim who leaks) a `session_id` could connect to the message endpoint and dispatch event handlers that execute with the **victim's identity and state**.
### Patches Fixed in **djust 1.0.7**. Each SSE session is bound to its owning principal at creation and cross-principal access is rejected; SSE session creation is additionally capped per principal.
### Workarounds Disable the SSE transport short of upgrading.
Are you affected?
Enter the version of the package you're using.