CVE-2026-31815
EUVD-2026-1090910.03.2026, 22:16
Unicorn adds modern reactive component functionality to your Django templates. Prior to 0.67.0, component state manipulation is possible in django-unicorn due to missing access control checks during property updates and method calls. An attacker can bypass the intended _is_public protection to modify internal attributes such as template_name or trigger protected methods. This vulnerability is fixed in 0.67.0.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| django-unicorn | unicorn | 𝑥 < 0.67.0 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration