High severity8.3OSV Advisory· Published Aug 12, 2024· Updated Jun 17, 2026
CVE-2024-42370
CVE-2024-42370
Description
Litestar is an Asynchronous Server Gateway Interface (ASGI) framework. In versions 2.10.0 and prior, Litestar's docs-preview.yml workflow is vulnerable to Environment Variable injection which may lead to secret exfiltration and repository manipulation. This issue grants a malicious actor the permission to write issues, read metadata, and write pull requests. In addition, the DOCS_PREVIEW_DEPLOY_TOKEN is exposed to the attacker. Commit 84d351e96aaa2a1338006d6e7221eded161f517b contains a fix for this issue.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
litestarPyPI | <= 2.10.0 | — |
Affected products
2- Range: 0.7.2, v0.0.1a, v0.1.0, …
Patches
Vulnerability mechanics
References
5- github.com/advisories/GHSA-4hq2-rpgc-r8r7ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2024-42370ghsaADVISORY
- github.com/litestar-org/litestar/blob/ffaf5616b19f6f0f4128209c8b49dbcb41568aa2/.github/workflows/docs-preview.ymlnvdWEB
- github.com/litestar-org/litestar/commit/84d351e96aaa2a1338006d6e7221eded161f517bnvdWEB
- github.com/litestar-org/litestar/security/advisories/GHSA-4hq2-rpgc-r8r7nvdWEB
News mentions
0No linked articles in our index yet.