{"id":"CVE-2026-61596","aliases":[],"url":"https://o3.security/vulnerability/CVE-2026-61596","summary":"djust has broken object-level access control (IDOR)","details":"### Impact\ndjust's per-object authorization (`get_object` + `has_object_permission`, ADR-017) was enforced on the WebSocket **mount** and **event** paths but **not** on three other render entry points: (a) the initial **HTTP GET** render, (b) **SPA `url_change`** navigation, and (c) `{% live_render %}` **embedded child** views. An authenticated user could therefore view (and on some paths act on) an object they are not authorized for by loading the page directly, navigating to it via SPA url-change, or composing it as an embedded child — a classic IDOR / broken object-level access control on object-scoped views.\n\n### Patches\nFixed in **djust 1.0.7**. All render entry points now route through a shared `enforce_object_permission` chokepoint: HTTP GET returns **403**, `url_change` emits a `permission_denied` frame and skips the render, and `{% live_render %}` (eager + lazy) refuses the embed. Views without a custom `get_object` are unaffected (no-op).\n\n### Workarounds\nNo reliable workaround short of upgrading. Do not expose object-scoped views through the HTTP-GET / url_change / live_render paths until patched.","published":"2026-09-16T22:06:02Z","modified":"2026-09-16T22:15:26.298462346Z","cvss":{"score":7.1,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[{"ecosystem":"PyPI","name":"djust","fixedVersion":"1.0.7"}],"fix":null,"references":[{"type":"WEB","url":"https://github.com/djust-org/djust/security/advisories/GHSA-c7c5-5j6r-q957"},{"type":"PACKAGE","url":"https://github.com/djust-org/djust"},{"type":"WEB","url":"https://github.com/djust-org/djust/releases/tag/v1.0.7"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-09-16T22:15:26.298462346Z"}}