In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsUpgrade djust to version 1.1.1 or higher.
djust is a Phoenix LiveView-style reactive components for Django with Rust-powered performance. Real-time UI updates over WebSocket, no JavaScript build step required.
Affected versions of this package are vulnerable to Improper Encoding or Escaping of Output via improper handling of template filters and context variables. An attacker can inject and execute arbitrary client-side scripts by supplying crafted input that is rendered unescaped in the output. This can occur through various template constructs, including the use of filters such as linenumbers, escape, unordered_list, safeseq, linebreaks, and the render_slot tag, as well as by reusing context variables previously marked as safe. No special configuration is required for exploitation.
This vulnerability can be mitigated by avoiding the use of |safe after any filter in a chain, not using safeseq or unordered_list on values that may be strings, and not reusing a context variable for both trusted and untrusted input.