HIGH8.8
PYSEC-2026-648
Kallithea Routes CSRF Bypass
Quick fix
PYSEC-2026-648 — kallithea: upgrade to the fixed version with the command below.
pip install --upgrade 'kallithea>=0.3.2'Details
Routes in Kallithea before 0.3.2 allows remote attackers to bypass the CSRF protection by using the GET HTTP request method.
Are you affected?
Enter the version of the package you're using.