THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-pvg3-6q9j-mj3x (medium) — djust's Django model serialization has no sensitive-field denylist: password hashes, privilege flags, and PII on a public view attribute are sent to the client

[GHSA] GHSA-pvg3-6q9j-mj3x (medium) — djust's Django model serialization has no sensitive-field denylist: password hashes, privilege flags, and PII on a public view attribute are sent to the client

medgithub_advisoriesPublished 2026-09-16

GHSA-pvg3-6q9j-mj3x Severity: medium CVE: CVE-2026-61588

djust's Django model serialization has no sensitive-field denylist: password hashes, privilege flags, and PII on a public view attribute are sent to the client

### Impact When a Django `Model` instance is assigned to a **public** view attribute, djust serialized it to the client with **no sensitive-field denylist** — sending fields such as

MITRE ATT&CK techniques

Indicators of compromise

Original source: https://github.com/advisories/GHSA-pvg3-6q9j-mj3x