cbcvebase.

Withastro Astro vulnerabilities

35 known vulnerabilities affecting withastro/astro.

Total CVEs
35
CISA KEV
0
Public exploits
5
Exploited in wild
3
Severity breakdown
CRITICAL1HIGH7MEDIUM23LOW4

Vulnerabilities

Page 2 of 2
CVE-2026-41067P4MEDIUMCVSS 6.1fixed in 6.1.62026-04-24
CVE-2026-41067 [MEDIUM] CWE-79 CVE-2026-41067: Astro is a web framework. Prior to 6.1.6, the defineScriptVars function in Astro's server-side rende Astro is a web framework. Prior to 6.1.6, the defineScriptVars function in Astro's server-side rendering pipeline uses a case-sensitive regex //g to sanitize values injected into inline tags via the define:vars directive. HTML parsers close elements case-insensitively and also accept whitespace or / before the closing >, allowing an attacker to bypas
nvd
CVE-2026-54298P4MEDIUMCVSS 6.1fixed in 7.0.62026-06-22
CVE-2026-54298 [MEDIUM] CWE-79 CVE-2026-54298: Astro is a web framework. Prior to 6.4.6, the spreadAttributes function in Astro's server-side rende Astro is a web framework. Prior to 6.4.6, the spreadAttributes function in Astro's server-side rendering pipeline iterates over object keys and passes them directly to addAttribute, which interpolates the key into the HTML output without escaping. When a developer uses the spread syntax {...props} on an HTML element and the object keys come from an u
nvd
CVE-2026-45028P4MEDIUMCVSS 6.1fixed in 6.1.102026-05-13
CVE-2026-45028 [MEDIUM] CWE-323 CVE-2026-45028: Astro is a web framework. Astro versions prior to 6.1.10 used AES-GCM encryption to protect the conf Astro is a web framework. Astro versions prior to 6.1.10 used AES-GCM encryption to protect the confidentiality and integrity of server island props and slots parameters, but did not bind the ciphertext to its intended component or parameter type. An attacker could replay one component's encrypted props (p) value as another component's slots (s) val
nvd
CVE-2026-54300P4MEDIUMCVSS 5.3fixed in 7.0.132026-06-22
CVE-2026-54300 [MEDIUM] CWE-918 CVE-2026-54300: @astrojs/netlify is an adapter that allows Astro to deploy your hybrid or server rendered site to Ne @astrojs/netlify is an adapter that allows Astro to deploy your hybrid or server rendered site to Netlify. Prior to 7.0.13, @astrojs/netlify converts Astro image.remotePatterns into Netlify Image CDN images.remote_images regular expressions with broader semantics than Astro's canonical matcher. A single wildcard hostname such as *.example.com is con
nvd
CVE-2026-73423P4MEDIUMCVSS 5.1v>= 7.0.0, < 7.0.62026-08-12
CVE-2026-73423 [MEDIUM] CWE-352 CVE-2026-73423: Astro is a web framework for content-driven websites. From 7.0.0 until 7.0.6, the composable astro/h Astro is a web framework for content-driven websites. From 7.0.0 until 7.0.6, the composable astro/hono pipeline installs security.checkOrigin only through the middleware() primitive, while actions() and pages() can dispatch to user code independently. Mounting actions() before middleware(), as in the examples/advanced-routing example and Cloudflare
nvd
CVE-2026-50146P4MEDIUMCVSS 6.1fixed in 6.3.32026-06-22
CVE-2026-50146 [MEDIUM] CWE-80 CVE-2026-50146: Astro is a web framework. Prior to 6.3.3, when a component uses a client:* directive, Astro inserts Astro is a web framework. Prior to 6.3.3, when a component uses a client:* directive, Astro inserts named slot content into a data-astro-template attribute without HTML escaping the slot name allowing an attacker to break out of the attribute context and inject arbitrary HTML, resulting in reflected XSS during SSR. This vulnerability is fixed in 6.3.3
nvd
CVE-2025-65019P4MEDIUMCVSS 6.1fixed in 5.15.92025-11-19
CVE-2025-65019 [MEDIUM] CWE-79 CVE-2025-65019: Astro is a web framework. Prior to version 5.15.9, when using Astro's Cloudflare adapter (@astrojs/c Astro is a web framework. Prior to version 5.15.9, when using Astro's Cloudflare adapter (@astrojs/cloudflare) with output: 'server', the image optimization endpoint (/_image) contains a critical vulnerability in the isRemoteAllowed() function that unconditionally allows data: protocol URLs. This enables Cross-Site Scripting (XSS) attacks through mal
nvd
CVE-2026-41322P4MEDIUMCVSS 5.3fixed in 10.0.52026-04-24
CVE-2026-41322 [MEDIUM] CWE-525 CVE-2026-41322: @astrojs/node allows Astro to deploy your SSR site to Node targets. Prior to 10.0.5, requesting a st @astrojs/node allows Astro to deploy your SSR site to Node targets. Prior to 10.0.5, requesting a static js/css resources from _astro path with an incorrect/malformed if-match header returns a 500 error with a one year cache lifetime instead of 412 in some cases. This has the effect that all subsequent requests to that file, regardless of if-match h
nvd
CVE-2025-64745P4MEDIUMCVSS 6.1v>= 5.2.0, < 5.15.62025-11-13
CVE-2025-64745 [MEDIUM] CWE-79 CVE-2025-64745: Astro is a web framework. Starting in version 5.2.0 and prior to version 5.15.6, a Reflected Cross-S Astro is a web framework. Starting in version 5.2.0 and prior to version 5.15.6, a Reflected Cross-Site Scripting (XSS) vulnerability exists in Astro's development server error pages when the `trailingSlash` configuration option is used. An attacker can inject arbitrary JavaScript code that executes in the victim's browser context by crafting a malic
nvd
CVE-2024-47885P4MEDIUMCVSS 5.4v>=3.0.0, < 4.16.12024-10-14
CVE-2024-47885 [MEDIUM] CWE-79 CVE-2024-47885: The Astro web framework has a DOM Clobbering gadget in the client-side router starting in version 3. The Astro web framework has a DOM Clobbering gadget in the client-side router starting in version 3.0.0 and prior to version 4.16.1. It can lead to cross-site scripting (XSS) in websites enables Astro's client-side routing and has *stored* attacker-controlled scriptless HTML elements (i.e., `iframe` tags with unsanitized `name` attributes) on the des
nvd
CVE-2026-59728P4MEDIUMCVSS 4.3v>= 1.0.0, < 4.0.192026-07-27
CVE-2026-59728 [MEDIUM] CWE-91 CVE-2026-59728: Astro is a web framework for content-driven websites. In versions 1.0.0 through 4.0.18, the source.t Astro is a web framework for content-driven websites. In versions 1.0.0 through 4.0.18, the source.title and enclosure.type item fields in packages/astro-rss/src/index.ts are interpolated directly into XML template strings without XML-character escaping before being parsed by fast-xml-parser. Both fields are validated only as z.string(), placing no r
nvd
CVE-2025-64757P4LOWCVSS 3.5fixed in 5.14.32025-11-19
CVE-2025-64757 [LOW] CWE-22 CVE-2025-64757: Astro is a web framework. Prior to version 5.14.3, a vulnerability has been identified in the Astro Astro is a web framework. Prior to version 5.14.3, a vulnerability has been identified in the Astro framework's development server that allows arbitrary local file read access through the image optimization endpoint. The vulnerability affects Astro development environments and allows remote attackers to read any image file accessible to the Node.js proce
nvd
CVE-2026-59730P4LOWCVSS 2.1v>= 8.1.0, < 11.0.22026-07-27
CVE-2026-59730 [LOW] CWE-601 CVE-2026-59730: Astro is a web framework for content-driven websites. In versions 8.1.0 through 11.0.1, when trailin Astro is a web framework for content-driven websites. In versions 8.1.0 through 11.0.1, when trailingSlash: 'always' is configured, the @astrojs/node standalone server's static file handler appends a trailing slash to request paths and issues a 301 redirect. Paths beginning with /\ (slash-backslash) were not recognized as internal paths, so the handler
nvd
CVE-2026-73425P4LOWCVSS 3.7fixed in 8.1.22026-08-12
CVE-2026-73425 [LOW] CWE-185 CVE-2026-73425: Astro is a web framework for content-driven websites. Prior to 8.1.2, the Astro Netlify adapter conv Astro is a web framework for content-driven websites. Prior to 8.1.2, the Astro Netlify adapter converts each image.remotePatterns entry into a regular expression written to .netlify/v1/config.json under images.remote_images for Netlify's Image CDN allowlist. In packages/integrations/netlify/src/index.ts, remotePatternToRegex() escapes dots in hostname
nvd
CVE-2026-59727P4LOWCVSS 2.1v>= 3.10.0, < 7.0.42026-07-27
CVE-2026-59727 [LOW] CWE-79 CVE-2026-59727: Astro is a web framework for content-driven websites. In versions 3.10.0 through 7.0.3, when a trans Astro is a web framework for content-driven websites. In versions 3.10.0 through 7.0.3, when a transition:persist, transition:scope, or transition:persist-props directive is applied to a client-hydrated (client:*) component, Astro copied the directive value onto the rendered element without HTML-escaping it. If a developer reflects attacker-controlled i
nvd
Withastro Astro vulnerabilities | cvebase