Improperly Controlled Modification of Dynamically-Determined Object Attributes Affecting djust package, versions [,1.0.7)


Severity

Recommended
0.0
high
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.43% (35th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications

Snyk Learn

Learn about Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerabilities in an interactive lesson.

Start learning
  • Snyk IDSNYK-PYTHON-DJUST-20158889
  • published27 Sept 2026
  • disclosed16 Sept 2026
  • creditUnknown

Introduced: 16 Sep 2026

NewCVE-2026-61598  (opens in a new tab)
CWE-915  (opens in a new tab)

How to fix?

Upgrade djust to version 1.0.7 or higher.

Overview

djust is a Phoenix LiveView-style reactive components for Django with Rust-powered performance. Real-time UI updates over WebSocket, no JavaScript build step required.

Affected versions of this package are vulnerable to Improperly Controlled Modification of Dynamically-Determined Object Attributes in the update_model process. An attacker can manipulate sensitive view attributes by sending crafted events with arbitrary field names and values over the WebSocket interface. This can result in unauthorized modification of business logic or authorization state, especially when public view attributes are used to store such information. Type coercion of values to match attribute types further facilitates exploitation.

Workaround

This vulnerability can be mitigated by explicitly setting allowed_model_fields on every view using dj-model or subclassing LiveView to the minimal list of bindable fields, and by avoiding storage of authorization or ownership state in public view attributes that are accessible alongside dj-model bindings.

CVSS Base Scores

version 4.0
version 3.1