THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-xx4j-w367-7247 (high) — djust authentication bypass: a login_required / on_mount LiveView mount redirect does not close the WebSocket, allowing an unauthenticated client to dispatch event-handler calls

[GHSA] GHSA-xx4j-w367-7247 (high) — djust authentication bypass: a login_required / on_mount LiveView mount redirect does not close the WebSocket, allowing an unauthenticated client to dispatch event-handler calls

medgithub_advisoriesPublished 2026-08-25

GHSA-xx4j-w367-7247 Severity: high CVE: CVE-2026-55571

djust authentication bypass: a login_required / on_mount LiveView mount redirect does not close the WebSocket, allowing an unauthenticated client to dispatch event-handler calls

### Impact

djust's `LiveViewConsumer` mounts a `LiveView` over a WebSocket. When a view is gated (`login_required` / `permission_required`, or an `on_mount` hook th

Indicators of compromise

Original source: https://github.com/advisories/GHSA-xx4j-w367-7247