CVE-2026-48060 is a vulnerability in the Litestar ASGI framework affecting versions prior to 2.20.0. When Litestar is deployed with both a template engine and CSRF protection enabled, the framework can render CSRF-related content without the automatic escaping normally applied by the template engine when configured according to the documented inline pattern. Because the contents of the CSRF cookie are excluded from escaping in this scenario, attacker-controlled input can be injected into rendered HTML. This creates an HTML injection condition that can be escalated to cross-site scripting if malicious script-capable markup is reflected into a victim’s browser.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This seven-file repository is a self-contained browser-based HTML/attribute-injection and XSS proof of concept for the claimed CVE-2026-48060 affecting Litestar CSRF token rendering. `litestar_app/app.py` creates a Litestar application with a single GET `/` route returning `templates/login.jinja`. The template renders `csrf_input` through `| safe`, providing the intended unsafe sink. `static/index.html` is the attacker page: it sets a malformed `csrftoken` cookie whose value begins with `"><script>...`, waits five seconds, and redirects the browser to the application. If Litestar incorporates that cookie-derived CSRF token into HTML without contextual escaping, the payload escapes an attribute and executes script. The Dockerfile runs both the vulnerable Litestar service on container port 80 and Python's static server on 8080; documented host mappings expose these as localhost:8000 and localhost:8001. The repository's version claims are inconsistent: the README identifies vulnerable Litestar 2.21.0, while `requirements.txt` pins 2.21.1. Additionally, the README's root-level Docker build command does not match the Dockerfile location under `litestar_app`, so the build context/invocation may need adjustment. The payload is a hard-coded alert, making this an operational demonstration rather than a customizable exploitation framework.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.