VYPR

Astro

by Withastro

npm: astro

Source repositories

CVEs (37)

  • CVE-2024-56140MedDec 18, 2024
    risk 0.31cvss 5.9epss 0.00

    Astro is a web framework for content-driven websites. In affected versions a bug in Astro’s CSRF-protection middleware allows requests to bypass CSRF checks. When the `security.checkOrigin` configuration option is set to `true`, Astro middleware will perform a CSRF check.…

  • CVE-2024-47885MedOct 14, 2024
    risk 0.31cvss 5.9epss 0.00

    The Astro web framework has a DOM Clobbering gadget in the client-side router starting in version 3.0.0 and prior to version 4.16.1. It can lead to cross-site scripting (XSS) in websites enables Astro's client-side routing and has *stored* attacker-controlled scriptless HTML…

  • CVE-2025-55207MedAug 15, 2025
    risk 0.29cvss epss 0.01

    Astro is a web framework for content-driven websites. Following CVE-2025-54793 there's still an Open Redirect vulnerability in a subset of Astro deployment scenarios prior to version 9.4.1. Astro 5.12.8 addressed CVE-2025-54793 where https://example.com//astro.build/press would…

  • CVE-2025-65019MedNov 19, 2025
    risk 0.28cvss 5.4epss 0.00

    Astro is a web framework. Prior to version 5.15.9, when using Astro's Cloudflare adapter (@astrojs/cloudflare) with output: 'server', the image optimization endpoint (/_image) contains a critical vulnerability in the isRemoteAllowed() function that unconditionally allows data:…

  • CVE-2024-56159MedDec 19, 2024
    risk 0.28cvss 5.3epss 0.01

    Astro is a web framework for content-driven websites. A bug in the build process allows any unauthenticated user to read parts of the server source code. During build, along with client assets such as css and font files, the sourcemap files **for the server code** are moved to a…

  • CVE-2026-73422MedAug 12, 2026
    risk 0.27cvss epss 0.00

    Astro is a web framework for content-driven websites. From 2.9.0 until 7.1.0, Astro's server-side View Transition CSS generator interpolates animation properties into an inline style element without escaping them for CSS and HTML contexts. An attacker-controlled View Transition…

  • CVE-2026-54298MedJun 22, 2026
    risk 0.27cvss 4.2epss 0.00

    Astro is a web framework. Prior to 6.4.6, the spreadAttributes function in Astro's server-side rendering pipeline iterates over object keys and passes them directly to addAttribute, which interpolates the key into the HTML output without escaping. When a developer uses the…

  • CVE-2026-33769MedMar 24, 2026
    risk 0.27cvss 5.3epss 0.00

    Astro is a web framework. From version 2.10.10 to before version 5.18.1, this issue concerns Astro's remotePatterns path enforcement for remote URLs used by server-side fetchers such as the image optimization endpoint. The path matching logic for /* wildcards is unanchored, so a…

  • CVE-2025-64765MedNov 19, 2025
    risk 0.27cvss 5.3epss 0.01

    Astro is a web framework. Prior to version 5.15.8, a mismatch exists between how Astro normalizes request paths for routing/rendering and how the application’s middleware reads the path for validation checks. Astro internally applies decodeURI() to determine which route to…

  • CVE-2026-73423MedAug 12, 2026
    risk 0.26cvss epss 0.00

    Astro is a web framework for content-driven websites. From 7.0.0 until 7.0.6, the composable astro/hono pipeline installs security.checkOrigin only through the middleware() primitive, while actions() and pages() can dispatch to user code independently. Mounting actions() before…

  • CVE-2026-59729MedJul 27, 2026
    risk 0.26cvss epss 0.00

    Astro is a web framework for content-driven websites. Versions prior to 7.0.6 are vulnerable to XSS through unescaped spread attribute names in renderHTMLElement. The fix for CVE-2026-54298 (GHSA-jrpj-wcv7-9fh9) added an INVALID_ATTR_NAME_CHAR guard to addAttribute() so that…

  • CVE-2026-59728MedJul 27, 2026
    risk 0.21cvss 4.3epss 0.00

    Astro is a web framework for content-driven websites. In versions 1.0.0 through 4.0.18, the source.title and enclosure.type item fields in packages/astro-rss/src/index.ts are interpolated directly into XML template strings without XML-character escaping before being parsed by…

  • CVE-2026-73425LowAug 12, 2026
    risk 0.17cvss 3.7epss 0.00

    Astro is a web framework for content-driven websites. Prior to 8.1.2, the Astro Netlify adapter converts each image.remotePatterns entry into a regular expression written to .netlify/v1/config.json under images.remote_images for Netlify's Image CDN allowlist. In…

  • CVE-2025-64757LowNov 19, 2025
    risk 0.16cvss 3.5epss 0.00

    Astro is a web framework. Prior to version 5.14.3, a vulnerability has been identified in the Astro framework's development server that allows arbitrary local file read access through the image optimization endpoint. The vulnerability affects Astro development environments and…

  • CVE-2025-64745LowNov 13, 2025
    risk 0.11cvss 2.7epss 0.00

    Astro is a web framework. Starting in version 5.2.0 and prior to version 5.15.6, a Reflected Cross-Site Scripting (XSS) vulnerability exists in Astro's development server error pages when the `trailingSlash` configuration option is used. An attacker can inject arbitrary…

  • CVE-2026-59730LowJul 27, 2026
    risk 0.07cvss epss 0.00

    Astro is a web framework for content-driven websites. In versions 8.1.0 through 11.0.1, when trailingSlash: 'always' is configured, the @astrojs/node standalone server's static file handler appends a trailing slash to request paths and issues a 301 redirect. Paths beginning with…

  • CVE-2026-59727LowJul 27, 2026
    risk 0.07cvss epss 0.00

    Astro is a web framework for content-driven websites. In versions 3.10.0 through 7.0.3, when a transition:persist, transition:scope, or transition:persist-props directive is applied to a client-hydrated (client:*) component, Astro copied the directive value onto the rendered…

Page 2 of 2