1.2.2
8 months ago
6 days ago
Known vulnerabilities in the djust package. This does not include vulnerabilities belonging to this package’s dependencies.
Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.
Fix for free| Vulnerability | Vulnerable Version |
|---|---|
djust is a Phoenix LiveView-style reactive components for Django with Rust-powered performance. Real-time UI updates over WebSocket, no JavaScript build step required. Affected versions of this package are vulnerable to Improper Encoding or Escaping of Output via improper handling of context safety grants during template variable rebinding. An attacker can inject and execute arbitrary scripts by supplying crafted input that is assigned to a context variable previously marked as safe, which is then rebound in template constructs such as How to fix Improper Encoding or Escaping of Output? Upgrade | [,1.1.2) |