djust-org
- Total products in the ecosystem
- 1
- Total vulnerabilities (90 days)
- 13
en
Verify to analyze this security profile
As of 09/16/2026, djust-org recorded 13 security vulnerabilities in the last 90 days across 1 products, including 10 rated High or above and 0 known exploited vulnerabilities (KEV) that should be prioritized for immediate remediation.
Over the last 90 days, djust had the most security vulnerabilities in the djust-org ecosystem, with 13 vulnerabilities—approximately 100% of the provider's total vulnerabilities during this period.
CyStack VulnScan continuously discovers assets, validates vulnerabilities, and helps security teams prioritize remediation across the organization.
Explore CyStack VulnScan| Vulnerability | Exploitation status | Fix | Affected product | Published | Severity |
|---|---|---|---|---|---|
CVE-2026-61598Client mass-assignment of arbitrary view attributes via the default dj-model update_model handler | Exploitation statusNot confirmed | FixYes | Affected productdjust | Published09/16/2026 | SeverityHigh |
CVE-2026-61590djust's observability endpoints are network-exposed: the localhost gate is an opt-in middleware the docs omit, and the views enforce only DEBUG | Exploitation statusNot confirmed | FixYes | Affected productdjust | Published09/16/2026 | SeverityHigh |
CVE-2026-55571djust authentication bypass: a login_required / on_mount LiveView mount redirect does not close the WebSocket, allowing an unauthenticated client to dispatch event-handler calls | Exploitation statusPublic exploit | FixYes | Affected productdjust | Published08/25/2026 | SeverityHigh |