THREAT OPS › Threat News › [GHSA] GHSA-4mf4-73j6-mvrw (medium) — djust is vulnerable to stored/reflected XSS via javascript: URLs in built-in component template tags
[GHSA] GHSA-4mf4-73j6-mvrw (medium) — djust is vulnerable to stored/reflected XSS via javascript: URLs in built-in component template tags
GHSA-4mf4-73j6-mvrw Severity: medium CVE: CVE-2026-61597
djust is vulnerable to stored/reflected XSS via javascript: URLs in built-in component template tags
### Impact Many djust built-in component template tags (`djust.components.templatetags.*`) render a developer/user-supplied URL into an `href` / `action` attribute, HTML-escaping it with `conditional_escape` but **never validating the URL s
MITRE ATT&CK techniques
- JavaScriptT1059.007
Indicators of compromise
- CVE-2026-61597cve
- https://`url
Original source: https://github.com/advisories/GHSA-4mf4-73j6-mvrw