Improper Encoding or Escaping of Output Affecting djust package, versions [,1.1.1)


Severity

Recommended
0.0
medium
0
10

CVSS assessment by Snyk's Security Team. Learn more

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-PYTHON-DJUST-20158887
  • published27 Sept 2026
  • disclosed17 Sept 2026
  • creditUnknown

Introduced: 17 Sep 2026

New CVE NOT AVAILABLE CWE-116  (opens in a new tab)
CWE-79  (opens in a new tab)

How to fix?

Upgrade djust to version 1.1.1 or higher.

Overview

djust is a Phoenix LiveView-style reactive components for Django with Rust-powered performance. Real-time UI updates over WebSocket, no JavaScript build step required.

Affected versions of this package are vulnerable to Improper Encoding or Escaping of Output via improper handling of template filters and context variables. An attacker can inject and execute arbitrary client-side scripts by supplying crafted input that is rendered unescaped in the output. This can occur through various template constructs, including the use of filters such as linenumbers, escape, unordered_list, safeseq, linebreaks, and the render_slot tag, as well as by reusing context variables previously marked as safe. No special configuration is required for exploitation.

Workaround

This vulnerability can be mitigated by avoiding the use of |safe after any filter in a chain, not using safeseq or unordered_list on values that may be strings, and not reusing a context variable for both trusted and untrusted input.

CVSS Base Scores

version 4.0
version 3.1