PyPi: Litestar

CVE-2024-42370

Safety vulnerability ID: 72610

This vulnerability was reviewed by experts

The information on this page was manually curated by our Cybersecurity Intelligence Team.

Created at Aug 12, 2024 Updated at Nov 20, 2024
Scan your Python projects for vulnerabilities →

Advisory

Litestar, an Asynchronous Server Gateway Interface (ASGI) framework, is vulnerable in affected versions due to an Environment Variable injection flaw in its `docs-preview.yml` workflow. This vulnerability could lead to secret exfiltration and repository manipulation, allowing a malicious actor to write issues, read metadata, and create pull requests. Additionally, the `DOCS_PREVIEW_DEPLOY_TOKEN` may be exposed to the attacker.

Affected package

litestar

Latest version: 2.13.0

Litestar - A production-ready, highly performant, extensible ASGI API Framework

Affected versions

Fixed versions

Vulnerability changelog

This vulnerability has no description

Resources

Use this package?

Scan your Python project for dependency vulnerabilities in two minutes

Scan your application