| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-4mf4-73j6-mvrw | djust is vulnerable to stored/reflected XSS via javascript: URLs in built-in component template tags |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Thu, 17 Sep 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Djust-org
Djust-org djust |
|
| Vendors & Products |
Djust-org
Djust-org djust |
Thu, 17 Sep 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 16 Sep 2026 22:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to version 1.0.7, many djust built-in component template tags (`djust.components.templatetags.*`) render a developer/user-supplied URL into an `href` / `action` attribute, HTML-escaping it with `conditional_escape` but never validating the URL scheme. HTML escaping prevents attribute breakout but does not neutralize a `javascript:` URI (which needs no escapable characters), so a URL value of `javascript:alert(document.cookie)` lands verbatim in `<a href="javascript:alert(document.cookie)">` and executes in the victim's session on click. Version 1.0.7 contains a fix. As a workaround, do not pass user-controllable URLs to the affected built-in component tags; pre-validate URL schemes in application code before binding them to component arguments. | |
| Title | djust is vulnerable to stored/reflected XSS via javascript: URLs in built-in component template tags | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-09-17T15:06:13.521Z
Reserved: 2026-07-10T17:12:17.238Z
Link: CVE-2026-61597
Updated: 2026-09-17T15:06:10.714Z
Status : Received
Published: 2026-09-16T22:17:03.187
Modified: 2026-09-17T16:17:33.180
Link: CVE-2026-61597
No data.
OpenCVE Enrichment
Updated: 2026-09-17T21:15:14Z
Github GHSA