top of page
perceptive_background_267k.jpg

Litestar is an Asynchronous Server Gateway Interface (ASGI) framework. Prior to version 2.20.0, Litestar instances which use a template engine in conjunction wi…

Published:

27 July 2026 at 22:00:00

Alert date:

28 July 2026 at 21:02:19

Source:

nvd.nist.gov

Click to open the original link from this advisory

Web Technologies

CVE-2026-48060 affects Litestar, an ASGI (Asynchronous Server Gateway Interface) Python web framework. Versions prior to 2.20.0 are vulnerable to HTML Injection that can be escalated to Cross-Site Scripting (XSS). The vulnerability arises because the CSRF cookie contents are excluded from automatic escaping by the template engine when configured following the official documentation recommendations. Attackers could exploit this flaw in Litestar instances that use a template engine alongside CSRF protection. The issue has been fully patched in Litestar version 2.20.0. Users are advised to upgrade immediately to mitigate the risk. A security advisory has been published on GitHub under GHSA-542p-wvx7-72m4.

Technical details

Mitigation steps:

Affected products:

Litestar

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Disclaimer: Deze website toont informatie afkomstig van externe bronnen. Perceptive aanvaardt geen verantwoordelijkheid voor de inhoud, juistheid of volledigheid van deze informatie.

bottom of page