THREAT OPS › Threat News › [GHSA] GHSA-xhhm-f6hp-2qwj (critical) — djust has an authorization bypass on the WebSocket/SSE mount path
[GHSA] GHSA-xhhm-f6hp-2qwj (critical) — djust has an authorization bypass on the WebSocket/SSE mount path
GHSA-xhhm-f6hp-2qwj Severity: critical CVE: CVE-2026-61594
djust has an authorization bypass on the WebSocket/SSE mount path
### Impact The live (WebSocket) transport authorizes a mount via `check_view_auth`, not Django's `View.dispatch()` chain. As a result, standard Django authorization — `LoginRequiredMixin`, `PermissionRequiredMixin`, `UserPassesTestMixin`, `@method_decorator(login_required,
Indicators of compromise
- CVE-2026-61594cve
Original source: https://github.com/advisories/GHSA-xhhm-f6hp-2qwj