CVE Feed

    Dashboard / CVE / CVE-2026-31815

    CVE-2026-31815

    Unicorn adds modern reactive component functionality to your Django templates. Prior to 0.67.0, component state manipulation is possible in django-unicorn due to missing access control checks during property updates and method calls. An attacker can bypass the intended _is_public protection to modify internal attributes such as template_name or trigger protected methods. This vulnerability is fixed in 0.67.0.

    Published:Mar 10, 2026
    Last Modified:Apr 16, 2026
    EPS:Mar 10, 2026
    EPSS Score:0.00073
    CVSS Score:5.3

    Affected Products

    Vendor
    Django-commons
    Product
    Django-unicorn
    Vendor
    Django-unicorn
    Product
    Unicorn

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High