CVE-2026-31815 identifies a missing access control vulnerability in django-unicorn versions prior to 0.67.0, a library for adding reactive component functionality to Django templates. This flaw allows an unauthenticated attacker to manipulate component state, bypass intended internal protections, and modify attributes such as template_name or trigger protected methods. Rated with a CVSS score of 5.3 (Medium), the vulnerability primarily impacts integrity, as an attacker can achieve low integrity modifications. Currently, there is no evidence of active exploitation, public exploit code availability, or significant community discussion regarding this vulnerability. Organizations using django-unicorn are advised to upgrade to version 0.67.0 or later to remediate this issue.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 0.67.0CPE matchmatch criteria | cpe:2.3:a:django-unicorn:unicorn:*:*:*:*:*:django:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.