THREAT OPS › Threat News › [GHSA] GHSA-pvg3-6q9j-mj3x (medium) — djust's Django model serialization has no sensitive-field denylist: password hashes, privilege flags, and PII on a public view attribute are sent to the client
[GHSA] GHSA-pvg3-6q9j-mj3x (medium) — djust's Django model serialization has no sensitive-field denylist: password hashes, privilege flags, and PII on a public view attribute are sent to the client
GHSA-pvg3-6q9j-mj3x Severity: medium CVE: CVE-2026-61588
djust's Django model serialization has no sensitive-field denylist: password hashes, privilege flags, and PII on a public view attribute are sent to the client
### Impact When a Django `Model` instance is assigned to a **public** view attribute, djust serialized it to the client with **no sensitive-field denylist** — sending fields such as
MITRE ATT&CK techniques
- CredentialsT1589.001
Indicators of compromise
- CVE-2026-61588cve
Original source: https://github.com/advisories/GHSA-pvg3-6q9j-mj3x