djust is vulnerable to stored/reflected XSS via javascript: URLs in built-in component template tags
Published Sep 16, 2026
5.1
MEDIUMCVSS 4.0
EPSS 0.41%
Description
djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to version 1.0.7, many djust built-in component template tags (`djust.components.templatetags.*`) render a developer/user-supplied URL into an `href` / `action` attribute, HTML-escaping it with `conditional_escape` but never validating the URL scheme. HTML escaping prevents attribute breakout but does not neutralize a `javascript:` URI (which needs no escapable characters), so a URL value of `javascript:alert(document.cookie)` lands verbatim in `<a href="javascript:alert(document.cookie)">` and executes in the victim's session on click. Version 1.0.7 contains a fix. As a workaround, do not pass user-controllable URLs to the affected built-in component tags; pre-validate URL schemes in application code before binding them to component arguments.
Affected products
-
- Version < 1.0.7StatusaffectedConstraints-
- Version
No data.
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (3)
- https://github.com/advisories/GHSA-4mf4-73j6-mvrw Advisory
- https://github.com/djust-org/djust/releases/tag/v1.0.7 x_refsource_MISC
- https://github.com/djust-org/djust/security/advisories/GHSA-4mf4-73j6-mvrw x_refsource_CONFIRM
| Link | Providers | Tags |
|---|---|---|
| https://github.com/advisories/GHSA-4mf4-73j6-mvrw | Advisory | |
| https://github.com/djust-org/djust/releases/tag/v1.0.7 | x_refsource_MISC | |
| https://github.com/djust-org/djust/security/advisories/GHSA-4mf4-73j6-mvrw | x_refsource_CONFIRM |
Change history (0)
No recorded changes yet.