CVE-2026-31815

MEDIUM

django-unicorn <0.67.0 - Auth Bypass

Title source: llm

Description

Unicorn adds modern reactive component functionality to your Django templates. Prior to 0.67.0, component state manipulation is possible in django-unicorn due to missing access control checks during property updates and method calls. An attacker can bypass the intended _is_public protection to modify internal attributes such as template_name or trigger protected methods. This vulnerability is fixed in 0.67.0.

Scores

CVSS v3 5.3
EPSS 0.0010
EPSS Percentile 27.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Details

CWE
CWE-284 CWE-915
Status published
Products (2)
django-unicorn/unicorn < 0.67.0
pypi/django-unicorn 0 - 0.67.0PyPI
Published Mar 10, 2026
Tracked Since Mar 11, 2026