The magical reactive component framework for Django
django_unicorn has critical vulnerabilities — do not use
Update to >= 0.62.0 to fix known vulnerabilities
| Severity | ID | Summary | Fixed in |
|---|---|---|---|
| medium | CVE-2026-31815 | django-unicorn affected by component state manipulation via unvalidated attribute access | 0.67.0 |
| critical | CVE-2025-24370 | Django-Unicorn Class Pollution Vulnerability, Leading to XSS, DoS and Authentication Bypass | 0.62.0 |
Get this data programmatically — free, no authentication.
curl https://depscope.dev/api/check/conda/django_unicornFirst published · 2023-03-23 21:46:27.466000+00:00
Last updated · 2025-04-22 14:58:37.458000+00:00