Executive brief
djust is a Django web framework templating system used to render dynamic content in web applications. Six separate bugs in djust's auto-escaping mechanism allow attackers to inject JavaScript code that executes in users' browsers, potentially stealing sessions, credentials, or personal data. Exploitation requires no special configuration and can occur through common template patterns like rendering user input with filters or reusing template variables.
Technical details
Six distinct defects in djust template auto-escaping allow attacker-controlled input to bypass HTML escaping and execute as live JavaScript. Vulnerabilities include: filters like linenumbers and linebreaks that fail to escape output, the escape filter acting as a no-op while claiming safety, safeseq/unordered_list incorrectly marking raw strings as safe, persistent safety markers that survive across multiple renders, custom tag handlers emitting unescaped returns, and the render_slot tag echoing context values without escaping. All six are present in 1.1.0 and fixed in 1.1.1.
Affected products
- djust djust 1.1.0 and earlier
Timeline
- 2026-09-17: disclosed