THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-4mf4-73j6-mvrw (medium) — djust is vulnerable to stored/reflected XSS via javascript: URLs in built-in component template tags

[GHSA] GHSA-4mf4-73j6-mvrw (medium) — djust is vulnerable to stored/reflected XSS via javascript: URLs in built-in component template tags

highgithub_advisoriesPublished 2026-09-16

GHSA-4mf4-73j6-mvrw Severity: medium CVE: CVE-2026-61597

djust is vulnerable to stored/reflected XSS via javascript: URLs in built-in component template tags

### Impact Many djust built-in component template tags (`djust.components.templatetags.*`) render a developer/user-supplied URL into an `href` / `action` attribute, HTML-escaping it with `conditional_escape` but **never validating the URL s

MITRE ATT&CK techniques

Indicators of compromise

Original source: https://github.com/advisories/GHSA-4mf4-73j6-mvrw