GHSA-f795-p5jw-j6g2HighCVSS 7.4
djust: SSE sessions are not bound to the authenticated user; the client-chosen session_id is the sole authorization capability (session hijack)
🔗 CVE IDs covered (1)
📋 Description
Impact
SSE sessions were keyed solely by a client-chosen session_id with no binding to the authenticated user — a control the WebSocket transport has but that was dropped on SSE. An attacker who learns (or a victim who leaks) a session_id could connect to the message endpoint and dispatch event handlers that execute with the victim's identity and state.
Patches
Fixed in djust 1.0.7. Each SSE session is bound to its owning principal at creation and cross-principal access is rejected; SSE session creation is additionally capped per principal.
Workarounds
Disable the SSE transport short of upgrading.
🎯 Affected products1
- pip/djust:< 1.0.7