
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-31815 is a component state manipulation vulnerability in django-unicorn, a library that adds reactive component functionality to Django templates. Due to missing access control checks during property updates and method calls, an unauthenticated attacker can bypass the intended _is_public protection mechanism to modify internal component attributes (such as template_name) or trigger protected methods. All versions prior to 0.67.0 are affected. The vulnerability was published on March 9, 2026, and carries a CVSS v3.1 base score of 5.3 (Medium) (GitHub Advisory, Github Advisory).
The root cause is classified as CWE-284 (Improper Access Control) and CWE-915 (Improperly Controlled Modification of Dynamically-Determined Object Attributes). The vulnerable logic resides in src/django_unicorn/views/action_parsers/call_method.py and src/django_unicorn/views/action_parsers/utils.py, where set_property_value() and _call_method_name() use Python's getattr/setattr directly on component instances without verifying whether the target attribute or method is marked as public via _is_public. An attacker exploits this by sending a crafted JSON payload to the django-unicorn message endpoint, specifying a protected attribute name (e.g., template_name) and an arbitrary value, requiring no authentication or special privileges (GitHub Advisory).
Successful exploitation allows an unauthenticated remote attacker to manipulate component internal state and force the server-side component to render arbitrary templates accessible within the application's configured template directories — for example, rendering admin layout templates from other installed Django applications. An attacker can also invoke internal methods such as reset() to disrupt component state. Remote Code Execution (RCE) is explicitly not possible via this vector, and availability is unaffected; the primary risk is limited integrity and potential low-level information disclosure through unauthorized template rendering (GitHub Advisory, Github Advisory).
A proof-of-concept (PoC) exploit with step-by-step instructions and a concrete JSON payload is publicly available in the GitHub Security Advisory (GitHub Advisory). There is no evidence of in-the-wild exploitation at this time, and no threat actor attribution has been reported. The EPSS score is approximately 0.03–0.10% (28th percentile), indicating a low near-term exploitation probability. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (Github Advisory).
/unicorn/message/<component-name>) exposed by the target application.template_name:{
"actionQueue": [
{
"type": "syncInput",
"payload": {
"name": "template_name",
"value": "admin/base.html"
}
}
],
"data": {},
"meta": ""
}self.template_name = "admin/base.html" and subsequent component re-rendering returns the content of the targeted template, bypassing intended access controls (GitHub Advisory)./unicorn/message/<component-name> endpoints containing JSON bodies with "name": "template_name" or other internal attribute names not normally set by the application frontend; requests originating from unknown or anomalous IP addresses.admin/base.html or templates from other installed apps) triggered by unicorn message requests; HTTP 200 responses to POST requests on the unicorn message endpoint with unusual payload structures.reset() method (GitHub Advisory).Upgrade django-unicorn to version 0.67.0 or later, which enforces proper access control checks in set_property_value() and _call_method_name() to prevent unauthorized attribute modification (GitHub Advisory). If immediate patching is not feasible, implement network-level access controls to restrict requests to django-unicorn message endpoints to trusted clients only. Review and audit any custom components for sensitive internal attributes that could be manipulated if the patch cannot be applied promptly.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."