THREAT OPS › Threat News › [GHSA] GHSA-c67v-vqrp-m5wj (high) — djust: Unsigned client state snapshot is restored as trusted view state (privilege escalation / state injection)
[GHSA] GHSA-c67v-vqrp-m5wj (high) — djust: Unsigned client state snapshot is restored as trusted view state (privilege escalation / state injection)
GHSA-c67v-vqrp-m5wj Severity: high CVE: CVE-2026-61591
djust: Unsigned client state snapshot is restored as trusted view state (privilege escalation / state injection)
### Impact For views that opt into state snapshots, the snapshot `state_json` embedded in the client page was restored on reconnect as **trusted** view state with no integrity check. A client could edit the unsigned `state_json` i
Indicators of compromise
- CVE-2026-61591cve
Original source: https://github.com/advisories/GHSA-c67v-vqrp-m5wj