What is CVE-2026-48060?
CVE-2026-48060 is an HTML Injection vulnerability in Litestar, an ASGI framework, affecting versions prior to 2.20.0 when using template engines with CSRF protection. The flaw can be escalated to Cross Site Scripting (XSS) due to the contents of the CSRF cookie. Upgrading Litestar to version 2.20.0 or later is recommended.
Azərbaycanca: CVE-2026-48060, Litestar ASGI framework-unun 2.20.0 versiyasından əvvəlki versiyalarında CSRF müdafiəsi ilə birlikdə şablon mühərriki istifadə edən tətbiqlərə təsir edən HTML Injection zəifliyidir. Bu boşluq, CSRF cookie məzmunu səbəbilə Cross Site Scripting (XSS) hücumlarına qədər irəliləyə bilər. Litestar-i 2.20.0 və ya daha yeni versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-79
FAQ2
Which versions of the Litestar framework are affected by CVE-2026-48060?
This vulnerability affects Litestar ASGI framework versions prior to 2.20.0.
What action should be taken to remediate CVE-2026-48060?
It is recommended to upgrade Litestar to version 2.20.0 or later.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.