THREAT OPS › Threat News › [GHSA] GHSA-pg97-jvmf-qfvc (high) — djust has Cross-Site Request Forgery on the Server-Sent-Events transport: a cross-origin page can drive a victim-authenticated SSE session
[GHSA] GHSA-pg97-jvmf-qfvc (high) — djust has Cross-Site Request Forgery on the Server-Sent-Events transport: a cross-origin page can drive a victim-authenticated SSE session
GHSA-pg97-jvmf-qfvc Severity: high CVE: CVE-2026-61593
djust has Cross-Site Request Forgery on the Server-Sent-Events transport: a cross-origin page can drive a victim-authenticated SSE session
### Impact The SSE client→server POST endpoints are `@csrf_exempt` and the SSE GET stream endpoint had no Origin check, so a cross-origin page could drive a victim-cookie-authenticated SSE session: force
MITRE ATT&CK techniques
- CredentialsT1589.001
Indicators of compromise
- CVE-2026-61593cve
Original source: https://github.com/advisories/GHSA-pg97-jvmf-qfvc