PT-2026-24466 · Unknown · Django-Unicorn

Rinz27

·

Publicado

2026-03-10

·

Atualizado

2026-03-11

·

CVE-2026-31815

CVSS v3.1

5.3

Média

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Unicorn versions prior to 0.67.0
Description A flaw exists in django-unicorn that allows manipulation of component state due to insufficient access control checks when updating properties and calling methods. An attacker can bypass the intended protection to modify internal attributes like template name or trigger protected methods. This impacts the integrity of the application by allowing unauthorized state changes within the reactive components.
Recommendations Update to version 0.67.0 or later.

Exploit

Correção

Improper Access Control

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-31815
GHSA-FFV6-JJ46-X367

Produtos afetados

Django-Unicorn