THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-c67v-vqrp-m5wj (high) — djust: Unsigned client state snapshot is restored as trusted view state (privilege escalation / state injection)

[GHSA] GHSA-c67v-vqrp-m5wj (high) — djust: Unsigned client state snapshot is restored as trusted view state (privilege escalation / state injection)

medgithub_advisoriesPublished 2026-09-16

GHSA-c67v-vqrp-m5wj Severity: high CVE: CVE-2026-61591

djust: Unsigned client state snapshot is restored as trusted view state (privilege escalation / state injection)

### Impact For views that opt into state snapshots, the snapshot `state_json` embedded in the client page was restored on reconnect as **trusted** view state with no integrity check. A client could edit the unsigned `state_json` i

Indicators of compromise

Original source: https://github.com/advisories/GHSA-c67v-vqrp-m5wj