CVE-2026-48060

HIGH

Litestar: HTML Injection Through CSRF Token

Title source: cna
STIX 2.1

Description

Litestar is an Asynchronous Server Gateway Interface (ASGI) framework. Prior to version 2.20.0, Litestar instances which use a template engine in conjunction with CSRF protection are vulnerable to HTML Injection which can be escalated to Cross Site Scripting due to the contents of the CSRF cookie being excluded from automatic escaping by the template engine when configured inline with documentation recommendations. This issue has been patched in version 2.20.0.

References (2)

Core 2

Scores

CVSS v3 8.1
EPSS 0.0028
EPSS Percentile 20.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Details

CWE
CWE-79
Status published
Products (1)
litestar-org/litestar < 2.20.0
Published Jul 28, 2026
Tracked Since Jul 29, 2026