VDB
Sign up
HIGH7.4

GHSA-f795-p5jw-j6g2

djust: SSE sessions are not bound to the authenticated user; the client-chosen session_id is the sole authorization capability (session hijack)

Quick fix

GHSA-f795-p5jw-j6g2 — djust: upgrade to the fixed version with the command below.

pip install --upgrade 'djust>=1.0.7'

Details

### Impact SSE sessions were keyed solely by a **client-chosen** `session_id` with no binding to the authenticated user — a control the WebSocket transport has but that was dropped on SSE. An attacker who learns (or a victim who leaks) a `session_id` could connect to the message endpoint and dispatch event handlers that execute with the **victim's identity and state**.

### Patches Fixed in **djust 1.0.7**. Each SSE session is bound to its owning principal at creation and cross-principal access is rejected; SSE session creation is additionally capped per principal.

### Workarounds Disable the SSE transport short of upgrading.

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI/djust
Introduced in: 0Fixed in: 1.0.7
Fixpip install --upgrade 'djust>=1.0.7'

References