Astro: Remote code execution through AVIF image optimization
Source: GitHub Advisory Database, pulled hourly. · Last checked Sep 21, 2026
Astro: Remote code execution through AVIF image optimization
Astro: Authorization bypass from missing path-segment boundary check when stripping the configured base
Astro: composable `astro/hono` pipeline bypasses `security.checkOrigin` when `middleware()` is absent or misordered
Astro: XSS via unescaped spread attribute names in renderHTMLElement (incomplete fix for CVE-2026-54298)
Astro: Cross-site scripting via unescaped transition:* directive values on hydrated islands
Astro: Authorization Bypass via Decode Iteration Limit and Rewrite Path Canonicalization Mismatch
Astro: Reflected XSS via unescaped View Transition animation properties
Astro: XSS via Unescaped Attribute Names in Spread Props
Astro: Host header SSRF in prerendered error page fetch
Astro: Reflected XSS via unescaped slot name
Astro: Server island encrypted parameters vulnerable to cross-component replay
Astro: XSS in define:vars via incomplete </script> tag sanitization
Astro: Remote allowlist bypass via unanchored matchPathname wildcard
Astro has an Authentication Bypass via Double URL Encoding, a bypass for CVE-2025-64765
Astro Cloudflare adapter has Stored Cross-site Scripting vulnerability in /_image endpoint
Astro's middleware authentication checks based on url.pathname can be bypassed via url encoded values
Astro vulnerable to reflected XSS via the server islands feature
Astro Development Server has Arbitrary Local File Read
Astro vulnerable to URL manipulation via headers, leading to middleware and CVE-2025-61925 bypass
Astro development server error page is vulnerable to reflected Cross-site Scripting
Astro's bypass of image proxy domain validation leads to SSRF and potential XSS
Astro's `X-Forwarded-Host` is reflected without validation
Astro allows unauthorized third-party images in _image endpoint
Astros's duplicate trailing slash feature leads to an open redirection security issue
Astro's server source code is exposed to the public if sourcemaps are enabled
Atro CSRF Middleware Bypass (security.checkOrigin)
DOM Clobbering Gadget found in astro's client-side router that leads to XSS