Geex-Arts Django-Jet Cross-Site Request Forgery Vulnerability in OAuth Handler

Vulnerability

A cross-site request forgery (CSRF) vulnerability has been identified in Geex-Arts Django-Jet versions up to 1.0.8. The issue arises in the OAuth Handler component, where an unknown function can be manipulated to execute a CSRF attack. This vulnerability can be exploited remotely, and the public availability of the exploit increases the risk of potential attacks.

Impact

Exploitation of this vulnerability allows for cross-site request forgery attacks, where an attacker can trick a user into performing actions they did not intend to.

Reproduction

The vulnerability can be reproduced by sending a crafted request that exploits the lack of object-level authorization in the OAuth flow. This can be done by accessing and modifying another staff user's dashboard module through the OAuth endpoints, bypassing authentication and ownership checks.

Remediation

No specific remediation is currently available, but it is recommended to monitor for updates from the Geex-Arts Django-Jet project.

Added: Jul 19, 2026, 6:24 AM
Updated: Jul 19, 2026, 6:24 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
0.6
exploitability
7.7
remediation
0.0
relevance
9.8
threat
6.4
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.