CVE-2026-84376
published 2026-09-02CVE-2026-84376: Astro is a web framework for content-driven websites. Prior to 7.2.4, Astro stripped a configured non-root base path from request pathnames using a…
PriorityP345medium6.3CVSS 4.0
AVNACLATPPRNUINVCLVILVANSCNSINSANEXCRXIRXARXMAVXMACXMATXMPRXMUIXMVCXMVIXMVAXMSCXMSIXMSAXSXAUXRXVXREXUX
EPSS
0.71%
51.7th percentile
Astro is a web framework for content-driven websites. Prior to 7.2.4, Astro stripped a configured non-root base path from request pathnames using a string-prefix check without verifying a path-segment boundary. With base "/app", a request to "/appX/admin" resolved internally to the protected "/admin" route while middleware observed "/appX/admin" in context.url.pathname. In applications that authorize base-prefixed routes by inspecting context.url.pathname, an unauthenticated remote attacker could bypass pathname-based middleware authorization and reach protected routes. This issue is fixed in version 7.2.4.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| astro | astro | >= 0 < 7.2.4 | 7.2.4 |
| withastro | astro | < 7.2.4 | 7.2.4 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Astro: Authorization bypass from missing path-segment boundary check when stripping the configured base
ghsa·2026-09-08
CVE-2026-84376 [MEDIUM] CWE-187 Astro: Authorization bypass from missing path-segment boundary check when stripping the configured base
Astro: Authorization bypass from missing path-segment boundary check when stripping the configured base
## Summary
Astro stripped a configured `base` path from request pathnames using a string-prefix check that did not verify a path-segment boundary. With `base: "/app"`, a request to `/appX/admin` was treated as being under the base and resolved internally to the `/admin` route, while middleware still observed the public pathname `/appX/admin`. Middleware that authorizes routes by inspecting `context.url.pathname` could therefore be bypassed.
## Impact
An unauthenticated remote attacker can bypass pathname-based middleware authorization in applications that:
- Configure a non-root `base`.
- Protect base-prefixed routes in middleware using `context.url.pathname`.
Because routing and m
VulDB
withastro Astro up to 7.2.3 Base Path improper authorization
vuldb·2026-09-02·CVSS 6.3
CVE-2026-84376 [MEDIUM] withastro Astro up to 7.2.3 Base Path improper authorization
A vulnerability classified as critical was found in withastro Astro up to 7.2.3. Affected by this vulnerability is an unknown functionality of the component Base Path. The manipulation results in improper authorization.
This vulnerability is cataloged as CVE-2026-84376. The attack may be launched remotely. There is no exploit available.
Upgrading the affected component is advised.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-09-02
Published