djust@1.0.8

Phoenix LiveView-style reactive components for Django with Rust-powered performance. Real-time UI updates over WebSocket, no JavaScript build step required.

  • latest version

    1.2.2

  • latest non vulnerable version

  • first published

    8 months ago

  • latest version published

    6 days ago

  • licenses detected

  • Direct Vulnerabilities

    Known vulnerabilities in the djust package. This does not include vulnerabilities belonging to this package’s dependencies.

    Fix vulnerabilities automatically

    Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.

    Fix for free
    VulnerabilityVulnerable Version
    • M
    Improper Encoding or Escaping of Output

    djust is a Phoenix LiveView-style reactive components for Django with Rust-powered performance. Real-time UI updates over WebSocket, no JavaScript build step required.

    Affected versions of this package are vulnerable to Improper Encoding or Escaping of Output via improper handling of template filters and context variables. An attacker can inject and execute arbitrary client-side scripts by supplying crafted input that is rendered unescaped in the output. This can occur through various template constructs, including the use of filters such as linenumbers, escape, unordered_list, safeseq, linebreaks, and the render_slot tag, as well as by reusing context variables previously marked as safe. No special configuration is required for exploitation.

    How to fix Improper Encoding or Escaping of Output?

    Upgrade djust to version 1.1.1 or higher.

    [,1.1.1)
    • H
    Improper Encoding or Escaping of Output

    djust is a Phoenix LiveView-style reactive components for Django with Rust-powered performance. Real-time UI updates over WebSocket, no JavaScript build step required.

    Affected versions of this package are vulnerable to Improper Encoding or Escaping of Output via improper handling of context safety grants during template variable rebinding. An attacker can inject and execute arbitrary scripts by supplying crafted input that is assigned to a context variable previously marked as safe, which is then rebound in template constructs such as {% with %}, {% for %}, {% include ... with %}, or assign tags. This can occur without the use of filter chains or the |safe filter anywhere in the template.

    How to fix Improper Encoding or Escaping of Output?

    Upgrade djust to version 1.1.2 or higher.

    [,1.1.2)