CVE-2026-48060: fallo de gravedad alta en litestar-org litestar
Litestar: HTML Injection Through CSRF Token
Publicada el
41Vexday Risk Score
Sin señal de explotación. Ella tiene prueba de concepto pública.
ssvc Attendcvss 8.1epss 0.4%
de la publicación al arma0 días
Publicada en NVD28 jul
1ª PoC19 may
probabilidad de explotación
0.4%top 68% de las CVE
explotación observada
noninguna fuente lo reporta
1 exploit(s) público(s)
Litestar is an Asynchronous Server Gateway Interface (ASGI) framework. Prior to version 2.20.0, Litestar instances which use a template engine in conjunction with CSRF protection are vulnerable to HTML Injection which can be escalated to Cross Site Scripting due to the contents of the CSRF cookie being excluded from automatic escaping by the template engine when configured inline with documentation recommendations. This issue has been patched in version 2.20.0.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N
Productos afectados
litestar-org · litestarPoCs públicas encontradas — 1
githubgithub.com/Blinky-Keys/CVE-2026-48060★ 0⚠ Recursos públicos, para evaluar la exposición de sistemas que controlas o estás autorizado a probar. Prueba solo con autorización.
CVEs relacionadas — litestar-org litestar
En el mismo producto, de las más peligrosas a las menos.
CVE-2024-52581HIGHLitestar allows unbounded resource consumption (DoS vulnerability)EPSS 0.8%CVE-2024-32982HIGHLitestar and Starlite affected by Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')EPSS 0.7%CVE-2024-42370HIGHLitestar repository vulnerable to Environment Variable injection in `docs-preview.yml` workflowEPSS 0.7%CVE-2026-25480MEDIUMFileStore key canonicalization collisions allow response cache mixup/poisoning (ASCII ord + Unicode NFKD)EPSS 0.6%CVE-2026-25478HIGHLitestar has a CORS origin allowlist bypass due to unescaped regex metacharacters in allowed originsEPSS 0.5%CVE-2025-59152HIGHX-Forwarded-For Header Spoofing Bypasses Litestar Rate LimitingEPSS 0.5%