THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-pg97-jvmf-qfvc (high) — djust has Cross-Site Request Forgery on the Server-Sent-Events transport: a cross-origin page can drive a victim-authenticated SSE session

[GHSA] GHSA-pg97-jvmf-qfvc (high) — djust has Cross-Site Request Forgery on the Server-Sent-Events transport: a cross-origin page can drive a victim-authenticated SSE session

medgithub_advisoriesPublished 2026-09-16

GHSA-pg97-jvmf-qfvc Severity: high CVE: CVE-2026-61593

djust has Cross-Site Request Forgery on the Server-Sent-Events transport: a cross-origin page can drive a victim-authenticated SSE session

### Impact The SSE client→server POST endpoints are `@csrf_exempt` and the SSE GET stream endpoint had no Origin check, so a cross-origin page could drive a victim-cookie-authenticated SSE session: force

MITRE ATT&CK techniques

Indicators of compromise

Original source: https://github.com/advisories/GHSA-pg97-jvmf-qfvc