{"id":"CVE-2026-61597","title":"djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance","summary":"djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to version 1.0.7, many djust built-in component template tags (`djust.components.templatetags.*`) render a developer/use…","severity":"medium","cvss":5.1,"cvssVector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N","cwe":["CWE-79"],"vendor":"djust-org","product":"djust","affected":["djust < 1.0.7"],"patched":["djust 1.0.7"],"published":"2026-09-16","updated":"2026-09-17","sourceUpdated":"2026-09-17T16:17:33.180","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-61597","references":[{"url":"https://github.com/djust-org/djust/releases/tag/v1.0.7","label":"security-advisories@github.com"},{"url":"https://github.com/djust-org/djust/security/advisories/GHSA-4mf4-73j6-mvrw","label":"security-advisories@github.com"},{"url":"https://github.com/advisories/GHSA-4mf4-73j6-mvrw"},{"url":"https://github.com/djust-org/djust"}],"tags":["nvd","cve.org","ghsa","pip","osv"],"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"partial","timestamp":"2026-09-17T15:06:07.029671Z"},"cvssSource":"cna","aliases":["GHSA-4mf4-73j6-mvrw"],"ecosystem":"pip","ingestedAt":"2026-09-16T22:06:50.816Z","epss":0.003,"epssPercentile":0.22812,"slug":"CVE-2026-61597","body":"## Overview\n\ndjust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to version 1.0.7, many djust built-in component template tags (`djust.components.templatetags.*`) render a developer/user-supplied URL into an `href` / `action` attribute, HTML-escaping it with `conditional_escape` but never validating the URL scheme. HTML escaping prevents attribute breakout but does not neutralize a `javascript:` URI (which needs no escapable characters), so a URL value of `javascript:alert(document.cookie)` lands verbatim in `<a href=\"javascript:alert(document.cookie)\">` and executes in the victim's session on click. Version 1.0.7 contains a fix. As a workaround, do not pass user-controllable URLs to the affected built-in component tags; pre-validate URL schemes in application code before binding them to component arguments.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.\n\n## Package advisory (CVE-2026-61597)\n\nAffected packages:\n\n- `djust < 1.0.7`\n\nPatched in:\n\n- `djust 1.0.7`\n\nSource: https://github.com/advisories/GHSA-4mf4-73j6-mvrw","depth":"sunlit","depthScore":28,"depthScoreParts":{"impact":28.1,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}