Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-ffv6-jj46-x367 | django-unicorn affected by component state manipulation via unvalidated attribute access |
Wed, 18 Mar 2026 19:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Django-unicorn
Django-unicorn unicorn |
|
| CPEs | cpe:2.3:a:django-unicorn:unicorn:*:*:*:*:*:django:*:* | |
| Vendors & Products |
Django-unicorn
Django-unicorn unicorn |
Wed, 11 Mar 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 11 Mar 2026 12:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Django-commons
Django-commons django-unicorn |
|
| Vendors & Products |
Django-commons
Django-commons django-unicorn |
Tue, 10 Mar 2026 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Unicorn adds modern reactive component functionality to your Django templates. Prior to 0.67.0, component state manipulation is possible in django-unicorn due to missing access control checks during property updates and method calls. An attacker can bypass the intended _is_public protection to modify internal attributes such as template_name or trigger protected methods. This vulnerability is fixed in 0.67.0. | |
| Title | django-unicorn affected by component state manipulation via unvalidated attribute access | |
| Weaknesses | CWE-284 CWE-915 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-03-11T14:18:26.595Z
Reserved: 2026-03-09T16:33:42.914Z
Link: CVE-2026-31815
Updated: 2026-03-11T14:18:22.134Z
Status : Analyzed
Published: 2026-03-10T22:16:19.000
Modified: 2026-03-18T19:36:52.713
Link: CVE-2026-31815
No data.
OpenCVE Enrichment
Updated: 2026-04-16T03:15:22Z
Github GHSA