CVE-2026-48060highCWE-79

CVE-2026-48060: fallo de gravedad alta en litestar-org litestar

Litestar: HTML Injection Through CSRF Token

Publicada el

41Vexday Risk Score

Sin señal de explotación. Ella tiene prueba de concepto pública.

ssvc Attendcvss 8.1epss 0.4%
de la publicación al arma0 días
Publicada en NVD28 jul
1ª PoC19 may
probabilidad de explotación
0.4%top 68% de las CVE
explotación observada
noninguna fuente lo reporta
1 exploit(s) público(s)
Litestar is an Asynchronous Server Gateway Interface (ASGI) framework. Prior to version 2.20.0, Litestar instances which use a template engine in conjunction with CSRF protection are vulnerable to HTML Injection which can be escalated to Cross Site Scripting due to the contents of the CSRF cookie being excluded from automatic escaping by the template engine when configured inline with documentation recommendations. This issue has been patched in version 2.20.0.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N
Productos afectados
litestar-org · litestar
PoCs públicas encontradas — 1
githubgithub.com/Blinky-Keys/CVE-2026-48060★ 0
⚠ Recursos públicos, para evaluar la exposición de sistemas que controlas o estás autorizado a probar. Prueba solo con autorización.