astro
Astro is a modern site builder with web best practices, performance, and DX front-of-mind.
Security Advisories for astro in npm
Moderate
about 1 month ago
Astro: composable `astro/hono` pipeline bypasses `security.checkOrigin` when `middleware()` is absent or misordered
npm
astro
Moderate
about 1 month ago
Astro: XSS via unescaped spread attribute names in renderHTMLElement (incomplete fix for CVE-2026-54298)
npm
astro
Low
about 1 month ago
Astro: Cross-site scripting via unescaped transition:* directive values on hydrated islands
npm
astro
High
about 1 month ago
Astro: Authorization Bypass via Decode Iteration Limit and Rewrite Path Canonicalization Mismatch
npm
astro
Moderate
about 1 month ago
Astro: Reflected XSS via unescaped View Transition animation properties
npm
astro
Low
4 months ago
Astro: Server island encrypted parameters vulnerable to cross-component replay
npm
astro
Moderate
9 months ago
Astro has an Authentication Bypass via Double URL Encoding, a bypass for CVE-2025-64765
npm
astro
Moderate
10 months ago
Astro Cloudflare adapter has Stored Cross-site Scripting vulnerability in /_image endpoint
npm
astro
Moderate
10 months ago
Astro's middleware authentication checks based on url.pathname can be bypassed via url encoded values
npm
astro
Moderate
10 months ago
Astro vulnerable to URL manipulation via headers, leading to middleware and CVE-2025-61925 bypass
npm
astro
Low
10 months ago
Astro development server error page is vulnerable to reflected Cross-site Scripting
npm
astro
High
10 months ago
Astro's bypass of image proxy domain validation leads to SSRF and potential XSS
npm
astro
Potential
High
12 months ago
Server-Side Request Forgery via /_image endpoint in Astro Cloudflare adapter
npm
@astrojs/cloudflare
Moderate
about 1 year ago
Astro allows unauthorized third-party images in _image endpoint
npm
astro, @astrojs/node
Potential
Moderate
about 1 year ago
@astrojs/node's trailing slash handling causes open redirect issue
npm
@astrojs/node
Moderate
about 1 year ago
Astros's duplicate trailing slash feature leads to an open redirection security issue
npm
astro
High
over 1 year ago
Astro's server source code is exposed to the public if sourcemaps are enabled
npm
astro
Moderate
almost 2 years ago
DOM Clobbering Gadget found in astro's client-side router that leads to XSS
npm
astro