THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-9395-2g46-rj3f (high) — djust: Six template-layer defects emit attacker-controlled markup unescaped (XSS)

[GHSA] GHSA-9395-2g46-rj3f (high) — djust: Six template-layer defects emit attacker-controlled markup unescaped (XSS)

medgithub_advisoriesPublished 2026-09-17

GHSA-9395-2g46-rj3f Severity: high CVE: None

djust: Six template-layer defects emit attacker-controlled markup unescaped (XSS)

Five independent defects in djust's template auto-escaping cause attacker-controlled input to be rendered as live markup where Django escapes it. All four are present in shipped 1.1.0 and are fixed in 1.1.1.

They share one shape: **a filter or grant that escapes nothing

Original source: https://github.com/advisories/GHSA-9395-2g46-rj3f