Geex-Arts Django-Jet OAuth Credential Revoke Handler Authorization Vulnerability

Vulnerability

An authorization vulnerability has been identified in Geex-Arts Django-Jet versions up to 1.0.8. The issue resides in the OAuth Credential Revoke Handler, where missing authorization allows for unauthorized revocation of credentials. This vulnerability can be exploited remotely, and a public exploit is available.

Impact

Exploitation of this vulnerability allows for unauthorized revocation of OAuth credentials, potentially disrupting integrations with third-party services.

Reproduction

The vulnerability can be reproduced by sending a GET request to the OAuth credential revoke endpoint for Google Analytics or Yandex Metrika, using a module primary key that does not belong to the user. The request can be made without authentication or ownership checks, bypassing necessary authorization requirements.

Remediation

Users are advised to update to a version of Geex-Arts Django-Jet that addresses this vulnerability. Consult the project's GitHub repository for the latest release information.

Added: Jul 19, 2026, 5:22 AM
Updated: Jul 19, 2026, 5:22 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
8.7
remediation
0.0
relevance
9.7
threat
6.4
urgency
2.9
incentive
4.2

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.