Astro vulnerabilities and security advisories
The newest reviewed advisories for astro and @astrojs/node on npm. Each one shows which versions are affected, which version fixes it, and a prompt that has your AI agent check your project and upgrade only if it needs to.
Get an email when Astro has a new one
Email alerts are coming soon. This page updates every hour.
$ latest 30 · 7 critical, high or exploited
- criticalSep 8, 2026
Astro: Remote code execution through AVIF image optimization
- astro < 7.2.8 · fixed in 7.2.8
GHSA-26w7-cxv4-gfx2prompt for your AI agent
paste into your agentA security advisory covers a package this project may use. Advisory: GHSA-26w7-cxv4-gfx2, severity critical What it is: Astro: Remote code execution through AVIF image optimization Affected packages: - astro: affected versions < 7.2.8. Fixed in 7.2.8. Details: https://github.com/advisories/GHSA-26w7-cxv4-gfx2 Please: 1. Check package.json and the lockfile (package-lock.json, pnpm-lock.yaml, yarn.lock or bun.lock) for these packages, including copies pulled in by other dependencies, and tell me which versions are installed. 2. If none of them are installed, or every installed version is outside the affected ranges, say so and change nothing. 3. If an installed version is affected, upgrade it to the fixed version for its release line or later. When the package only comes in through another dependency, upgrade that dependency, or add an override or resolution if it has no fixed release yet. 4. If there is no fixed version, read the advisory and apply its workaround, or tell me the options. 5. Reinstall, run the build and the tests, and fix anything the upgrade breaks. 6. Tell me what you changed and which versions are installed now. - mediumSep 8, 2026
Astro: Authorization bypass from missing path-segment boundary check when stripping the configured base
- astro <= 7.2.3 · fixed in 7.2.4
GHSA-376h-93r7-7g6fCVE-2026-84376prompt for your AI agent
paste into your agentA security advisory covers a package this project may use. Advisory: GHSA-376h-93r7-7g6f (CVE-2026-84376), severity medium What it is: Astro: Authorization bypass from missing path-segment boundary check when stripping the configured base Affected packages: - astro: affected versions <= 7.2.3. Fixed in 7.2.4. Details: https://github.com/advisories/GHSA-376h-93r7-7g6f Please: 1. Check package.json and the lockfile (package-lock.json, pnpm-lock.yaml, yarn.lock or bun.lock) for these packages, including copies pulled in by other dependencies, and tell me which versions are installed. 2. If none of them are installed, or every installed version is outside the affected ranges, say so and change nothing. 3. If an installed version is affected, upgrade it to the fixed version for its release line or later. When the package only comes in through another dependency, upgrade that dependency, or add an override or resolution if it has no fixed release yet. 4. If there is no fixed version, read the advisory and apply its workaround, or tell me the options. 5. Reinstall, run the build and the tests, and fix anything the upgrade breaks. 6. Tell me what you changed and which versions are installed now. - mediumJul 20, 2026
Astro: composable `astro/hono` pipeline bypasses `security.checkOrigin` when `middleware()` is absent or misordered
- astro >= 7.0.0, < 7.0.6 · fixed in 7.0.6
GHSA-8mv7-9c27-98vcCVE-2026-73423prompt for your AI agent
paste into your agentA security advisory covers a package this project may use. Advisory: GHSA-8mv7-9c27-98vc (CVE-2026-73423), severity medium What it is: Astro: composable `astro/hono` pipeline bypasses `security.checkOrigin` when `middleware()` is absent or misordered Affected packages: - astro: affected versions >= 7.0.0, < 7.0.6. Fixed in 7.0.6. Details: https://github.com/advisories/GHSA-8mv7-9c27-98vc Please: 1. Check package.json and the lockfile (package-lock.json, pnpm-lock.yaml, yarn.lock or bun.lock) for these packages, including copies pulled in by other dependencies, and tell me which versions are installed. 2. If none of them are installed, or every installed version is outside the affected ranges, say so and change nothing. 3. If an installed version is affected, upgrade it to the fixed version for its release line or later. When the package only comes in through another dependency, upgrade that dependency, or add an override or resolution if it has no fixed release yet. 4. If there is no fixed version, read the advisory and apply its workaround, or tell me the options. 5. Reinstall, run the build and the tests, and fix anything the upgrade breaks. 6. Tell me what you changed and which versions are installed now. - lowJul 20, 2026
@astrojs/node: Backslash-prefixed paths not recognized as internal by trailing-slash redirect
- @astrojs/node >= 8.1.0, < 11.0.2 · fixed in 11.0.2
GHSA-r557-wffq-wvrcCVE-2026-59730prompt for your AI agent
paste into your agentA security advisory covers a package this project may use. Advisory: GHSA-r557-wffq-wvrc (CVE-2026-59730), severity low What it is: @astrojs/node: Backslash-prefixed paths not recognized as internal by trailing-slash redirect Affected packages: - @astrojs/node: affected versions >= 8.1.0, < 11.0.2. Fixed in 11.0.2. Details: https://github.com/advisories/GHSA-r557-wffq-wvrc Please: 1. Check package.json and the lockfile (package-lock.json, pnpm-lock.yaml, yarn.lock or bun.lock) for these packages, including copies pulled in by other dependencies, and tell me which versions are installed. 2. If none of them are installed, or every installed version is outside the affected ranges, say so and change nothing. 3. If an installed version is affected, upgrade it to the fixed version for its release line or later. When the package only comes in through another dependency, upgrade that dependency, or add an override or resolution if it has no fixed release yet. 4. If there is no fixed version, read the advisory and apply its workaround, or tell me the options. 5. Reinstall, run the build and the tests, and fix anything the upgrade breaks. 6. Tell me what you changed and which versions are installed now. - mediumJul 20, 2026
Astro: XSS via unescaped spread attribute names in renderHTMLElement (incomplete fix for CVE-2026-54298)
- astro < 7.0.6 · fixed in 7.0.6
GHSA-f48w-9m4c-m7f5CVE-2026-59729prompt for your AI agent
paste into your agentA security advisory covers a package this project may use. Advisory: GHSA-f48w-9m4c-m7f5 (CVE-2026-59729), severity medium What it is: Astro: XSS via unescaped spread attribute names in renderHTMLElement (incomplete fix for CVE-2026-54298) Affected packages: - astro: affected versions < 7.0.6. Fixed in 7.0.6. Details: https://github.com/advisories/GHSA-f48w-9m4c-m7f5 Please: 1. Check package.json and the lockfile (package-lock.json, pnpm-lock.yaml, yarn.lock or bun.lock) for these packages, including copies pulled in by other dependencies, and tell me which versions are installed. 2. If none of them are installed, or every installed version is outside the affected ranges, say so and change nothing. 3. If an installed version is affected, upgrade it to the fixed version for its release line or later. When the package only comes in through another dependency, upgrade that dependency, or add an override or resolution if it has no fixed release yet. 4. If there is no fixed version, read the advisory and apply its workaround, or tell me the options. 5. Reinstall, run the build and the tests, and fix anything the upgrade breaks. 6. Tell me what you changed and which versions are installed now. - lowJul 20, 2026
Astro: Cross-site scripting via unescaped transition:* directive values on hydrated islands
- astro >= 3.10.0, < 7.0.4 · fixed in 7.0.4
GHSA-7pw4-f3q4-r2p2CVE-2026-59727prompt for your AI agent
paste into your agentA security advisory covers a package this project may use. Advisory: GHSA-7pw4-f3q4-r2p2 (CVE-2026-59727), severity low What it is: Astro: Cross-site scripting via unescaped transition:* directive values on hydrated islands Affected packages: - astro: affected versions >= 3.10.0, < 7.0.4. Fixed in 7.0.4. Details: https://github.com/advisories/GHSA-7pw4-f3q4-r2p2 Please: 1. Check package.json and the lockfile (package-lock.json, pnpm-lock.yaml, yarn.lock or bun.lock) for these packages, including copies pulled in by other dependencies, and tell me which versions are installed. 2. If none of them are installed, or every installed version is outside the affected ranges, say so and change nothing. 3. If an installed version is affected, upgrade it to the fixed version for its release line or later. When the package only comes in through another dependency, upgrade that dependency, or add an override or resolution if it has no fixed release yet. 4. If there is no fixed version, read the advisory and apply its workaround, or tell me the options. 5. Reinstall, run the build and the tests, and fix anything the upgrade breaks. 6. Tell me what you changed and which versions are installed now. - highJul 20, 2026
Astro: Authorization Bypass via Decode Iteration Limit and Rewrite Path Canonicalization Mismatch
- astro >= 6.4.7, < 6.4.8 · fixed in 6.4.8
GHSA-vj59-8hwv-xxmvCVE-2026-59731prompt for your AI agent
paste into your agentA security advisory covers a package this project may use. Advisory: GHSA-vj59-8hwv-xxmv (CVE-2026-59731), severity high What it is: Astro: Authorization Bypass via Decode Iteration Limit and Rewrite Path Canonicalization Mismatch Affected packages: - astro: affected versions >= 6.4.7, < 6.4.8. Fixed in 6.4.8. Details: https://github.com/advisories/GHSA-vj59-8hwv-xxmv Please: 1. Check package.json and the lockfile (package-lock.json, pnpm-lock.yaml, yarn.lock or bun.lock) for these packages, including copies pulled in by other dependencies, and tell me which versions are installed. 2. If none of them are installed, or every installed version is outside the affected ranges, say so and change nothing. 3. If an installed version is affected, upgrade it to the fixed version for its release line or later. When the package only comes in through another dependency, upgrade that dependency, or add an override or resolution if it has no fixed release yet. 4. If there is no fixed version, read the advisory and apply its workaround, or tell me the options. 5. Reinstall, run the build and the tests, and fix anything the upgrade breaks. 6. Tell me what you changed and which versions are installed now. - mediumJul 20, 2026
Astro: Reflected XSS via unescaped View Transition animation properties
- astro >= 2.9.0, <= 7.0.9 · fixed in 7.1.0
GHSA-4g3v-8h47-v7g6CVE-2026-73422prompt for your AI agent
paste into your agentA security advisory covers a package this project may use. Advisory: GHSA-4g3v-8h47-v7g6 (CVE-2026-73422), severity medium What it is: Astro: Reflected XSS via unescaped View Transition animation properties Affected packages: - astro: affected versions >= 2.9.0, <= 7.0.9. Fixed in 7.1.0. Details: https://github.com/advisories/GHSA-4g3v-8h47-v7g6 Please: 1. Check package.json and the lockfile (package-lock.json, pnpm-lock.yaml, yarn.lock or bun.lock) for these packages, including copies pulled in by other dependencies, and tell me which versions are installed. 2. If none of them are installed, or every installed version is outside the affected ranges, say so and change nothing. 3. If an installed version is affected, upgrade it to the fixed version for its release line or later. When the package only comes in through another dependency, upgrade that dependency, or add an override or resolution if it has no fixed release yet. 4. If there is no fixed version, read the advisory and apply its workaround, or tell me the options. 5. Reinstall, run the build and the tests, and fix anything the upgrade breaks. 6. Tell me what you changed and which versions are installed now. - mediumJun 16, 2026
Astro: XSS via Unescaped Attribute Names in Spread Props
- astro < 6.4.6 · fixed in 6.4.6
GHSA-jrpj-wcv7-9fh9CVE-2026-54298prompt for your AI agent
paste into your agentA security advisory covers a package this project may use. Advisory: GHSA-jrpj-wcv7-9fh9 (CVE-2026-54298), severity medium What it is: Astro: XSS via Unescaped Attribute Names in Spread Props Affected packages: - astro: affected versions < 6.4.6. Fixed in 6.4.6. Details: https://github.com/advisories/GHSA-jrpj-wcv7-9fh9 Please: 1. Check package.json and the lockfile (package-lock.json, pnpm-lock.yaml, yarn.lock or bun.lock) for these packages, including copies pulled in by other dependencies, and tell me which versions are installed. 2. If none of them are installed, or every installed version is outside the affected ranges, say so and change nothing. 3. If an installed version is affected, upgrade it to the fixed version for its release line or later. When the package only comes in through another dependency, upgrade that dependency, or add an override or resolution if it has no fixed release yet. 4. If there is no fixed version, read the advisory and apply its workaround, or tell me the options. 5. Reinstall, run the build and the tests, and fix anything the upgrade breaks. 6. Tell me what you changed and which versions are installed now. - highJun 16, 2026
Astro: Host header SSRF in prerendered error page fetch
- astro < 6.4.6 · fixed in 6.4.6
GHSA-2pvr-wf23-7pc7CVE-2026-54299prompt for your AI agent
paste into your agentA security advisory covers a package this project may use. Advisory: GHSA-2pvr-wf23-7pc7 (CVE-2026-54299), severity high What it is: Astro: Host header SSRF in prerendered error page fetch Affected packages: - astro: affected versions < 6.4.6. Fixed in 6.4.6. Details: https://github.com/advisories/GHSA-2pvr-wf23-7pc7 Please: 1. Check package.json and the lockfile (package-lock.json, pnpm-lock.yaml, yarn.lock or bun.lock) for these packages, including copies pulled in by other dependencies, and tell me which versions are installed. 2. If none of them are installed, or every installed version is outside the affected ranges, say so and change nothing. 3. If an installed version is affected, upgrade it to the fixed version for its release line or later. When the package only comes in through another dependency, upgrade that dependency, or add an override or resolution if it has no fixed release yet. 4. If there is no fixed version, read the advisory and apply its workaround, or tell me the options. 5. Reinstall, run the build and the tests, and fix anything the upgrade breaks. 6. Tell me what you changed and which versions are installed now. - highJun 16, 2026
Astro: Reflected XSS via unescaped slot name
- astro < 6.3.3 · fixed in 6.3.3
GHSA-8hv8-536x-4wqpCVE-2026-50146prompt for your AI agent
paste into your agentA security advisory covers a package this project may use. Advisory: GHSA-8hv8-536x-4wqp (CVE-2026-50146), severity high What it is: Astro: Reflected XSS via unescaped slot name Affected packages: - astro: affected versions < 6.3.3. Fixed in 6.3.3. Details: https://github.com/advisories/GHSA-8hv8-536x-4wqp Please: 1. Check package.json and the lockfile (package-lock.json, pnpm-lock.yaml, yarn.lock or bun.lock) for these packages, including copies pulled in by other dependencies, and tell me which versions are installed. 2. If none of them are installed, or every installed version is outside the affected ranges, say so and change nothing. 3. If an installed version is affected, upgrade it to the fixed version for its release line or later. When the package only comes in through another dependency, upgrade that dependency, or add an override or resolution if it has no fixed release yet. 4. If there is no fixed version, read the advisory and apply its workaround, or tell me the options. 5. Reinstall, run the build and the tests, and fix anything the upgrade breaks. 6. Tell me what you changed and which versions are installed now. - lowMay 13, 2026
Astro: Server island encrypted parameters vulnerable to cross-component replay
- astro < 6.1.10 · fixed in 6.1.10
GHSA-xr5h-phrj-8vxvCVE-2026-45028prompt for your AI agent
paste into your agentA security advisory covers a package this project may use. Advisory: GHSA-xr5h-phrj-8vxv (CVE-2026-45028), severity low What it is: Astro: Server island encrypted parameters vulnerable to cross-component replay Affected packages: - astro: affected versions < 6.1.10. Fixed in 6.1.10. Details: https://github.com/advisories/GHSA-xr5h-phrj-8vxv Please: 1. Check package.json and the lockfile (package-lock.json, pnpm-lock.yaml, yarn.lock or bun.lock) for these packages, including copies pulled in by other dependencies, and tell me which versions are installed. 2. If none of them are installed, or every installed version is outside the affected ranges, say so and change nothing. 3. If an installed version is affected, upgrade it to the fixed version for its release line or later. When the package only comes in through another dependency, upgrade that dependency, or add an override or resolution if it has no fixed release yet. 4. If there is no fixed version, read the advisory and apply its workaround, or tell me the options. 5. Reinstall, run the build and the tests, and fix anything the upgrade breaks. 6. Tell me what you changed and which versions are installed now. - mediumApr 23, 2026
Astro: Cache Poisoning due to incorrect error handling when if-match header is malformed
- @astrojs/node < 10.0.5 · fixed in 10.0.5
GHSA-c57f-mm3j-27q9CVE-2026-41322prompt for your AI agent
paste into your agentA security advisory covers a package this project may use. Advisory: GHSA-c57f-mm3j-27q9 (CVE-2026-41322), severity medium What it is: Astro: Cache Poisoning due to incorrect error handling when if-match header is malformed Affected packages: - @astrojs/node: affected versions < 10.0.5. Fixed in 10.0.5. Details: https://github.com/advisories/GHSA-c57f-mm3j-27q9 Please: 1. Check package.json and the lockfile (package-lock.json, pnpm-lock.yaml, yarn.lock or bun.lock) for these packages, including copies pulled in by other dependencies, and tell me which versions are installed. 2. If none of them are installed, or every installed version is outside the affected ranges, say so and change nothing. 3. If an installed version is affected, upgrade it to the fixed version for its release line or later. When the package only comes in through another dependency, upgrade that dependency, or add an override or resolution if it has no fixed release yet. 4. If there is no fixed version, read the advisory and apply its workaround, or tell me the options. 5. Reinstall, run the build and the tests, and fix anything the upgrade breaks. 6. Tell me what you changed and which versions are installed now. - mediumApr 21, 2026
Astro: XSS in define:vars via incomplete </script> tag sanitization
- astro < 6.1.6 · fixed in 6.1.6
GHSA-j687-52p2-xcffCVE-2026-41067prompt for your AI agent
paste into your agentA security advisory covers a package this project may use. Advisory: GHSA-j687-52p2-xcff (CVE-2026-41067), severity medium What it is: Astro: XSS in define:vars via incomplete </script> tag sanitization Affected packages: - astro: affected versions < 6.1.6. Fixed in 6.1.6. Details: https://github.com/advisories/GHSA-j687-52p2-xcff Please: 1. Check package.json and the lockfile (package-lock.json, pnpm-lock.yaml, yarn.lock or bun.lock) for these packages, including copies pulled in by other dependencies, and tell me which versions are installed. 2. If none of them are installed, or every installed version is outside the affected ranges, say so and change nothing. 3. If an installed version is affected, upgrade it to the fixed version for its release line or later. When the package only comes in through another dependency, upgrade that dependency, or add an override or resolution if it has no fixed release yet. 4. If there is no fixed version, read the advisory and apply its workaround, or tell me the options. 5. Reinstall, run the build and the tests, and fix anything the upgrade breaks. 6. Tell me what you changed and which versions are installed now. - lowMar 26, 2026
Astro: Remote allowlist bypass via unanchored matchPathname wildcard
- astro >= 2.10.10, < 5.18.1 · fixed in 5.18.1
GHSA-g735-7g2w-hh3fCVE-2026-33769prompt for your AI agent
paste into your agentA security advisory covers a package this project may use. Advisory: GHSA-g735-7g2w-hh3f (CVE-2026-33769), severity low What it is: Astro: Remote allowlist bypass via unanchored matchPathname wildcard Affected packages: - astro: affected versions >= 2.10.10, < 5.18.1. Fixed in 5.18.1. Details: https://github.com/advisories/GHSA-g735-7g2w-hh3f Please: 1. Check package.json and the lockfile (package-lock.json, pnpm-lock.yaml, yarn.lock or bun.lock) for these packages, including copies pulled in by other dependencies, and tell me which versions are installed. 2. If none of them are installed, or every installed version is outside the affected ranges, say so and change nothing. 3. If an installed version is affected, upgrade it to the fixed version for its release line or later. When the package only comes in through another dependency, upgrade that dependency, or add an override or resolution if it has no fixed release yet. 4. If there is no fixed version, read the advisory and apply its workaround, or tell me the options. 5. Reinstall, run the build and the tests, and fix anything the upgrade breaks. 6. Tell me what you changed and which versions are installed now. - mediumMar 24, 2026
Astro: Memory exhaustion DoS due to missing request body size limit in Server Islands
- @astrojs/node < 10.0.0 · fixed in 10.0.0
GHSA-3rmj-9m5h-8fpvCVE-2026-29772prompt for your AI agent
paste into your agentA security advisory covers a package this project may use. Advisory: GHSA-3rmj-9m5h-8fpv (CVE-2026-29772), severity medium What it is: Astro: Memory exhaustion DoS due to missing request body size limit in Server Islands Affected packages: - @astrojs/node: affected versions < 10.0.0. Fixed in 10.0.0. Details: https://github.com/advisories/GHSA-3rmj-9m5h-8fpv Please: 1. Check package.json and the lockfile (package-lock.json, pnpm-lock.yaml, yarn.lock or bun.lock) for these packages, including copies pulled in by other dependencies, and tell me which versions are installed. 2. If none of them are installed, or every installed version is outside the affected ranges, say so and change nothing. 3. If an installed version is affected, upgrade it to the fixed version for its release line or later. When the package only comes in through another dependency, upgrade that dependency, or add an override or resolution if it has no fixed release yet. 4. If there is no fixed version, read the advisory and apply its workaround, or tell me the options. 5. Reinstall, run the build and the tests, and fix anything the upgrade breaks. 6. Tell me what you changed and which versions are installed now. - mediumFeb 25, 2026
Astro has memory exhaustion DoS due to missing request body size limit in Server Actions
- @astrojs/node >= 9.0.0, < 9.5.4 · fixed in 9.5.4
GHSA-jm64-8m5q-4qh8CVE-2026-27729prompt for your AI agent
paste into your agentA security advisory covers a package this project may use. Advisory: GHSA-jm64-8m5q-4qh8 (CVE-2026-27729), severity medium What it is: Astro has memory exhaustion DoS due to missing request body size limit in Server Actions Affected packages: - @astrojs/node: affected versions >= 9.0.0, < 9.5.4. Fixed in 9.5.4. Details: https://github.com/advisories/GHSA-jm64-8m5q-4qh8 Please: 1. Check package.json and the lockfile (package-lock.json, pnpm-lock.yaml, yarn.lock or bun.lock) for these packages, including copies pulled in by other dependencies, and tell me which versions are installed. 2. If none of them are installed, or every installed version is outside the affected ranges, say so and change nothing. 3. If an installed version is affected, upgrade it to the fixed version for its release line or later. When the package only comes in through another dependency, upgrade that dependency, or add an override or resolution if it has no fixed release yet. 4. If there is no fixed version, read the advisory and apply its workaround, or tell me the options. 5. Reinstall, run the build and the tests, and fix anything the upgrade breaks. 6. Tell me what you changed and which versions are installed now. - mediumFeb 25, 2026
Astro is vulnerable to SSRF due to missing allowlist enforcement in remote image inferSize
- @astrojs/node >= 9.0.0, < 9.5.4 · fixed in 9.5.4
GHSA-cj9f-h6r6-4cx2CVE-2026-27829prompt for your AI agent
paste into your agentA security advisory covers a package this project may use. Advisory: GHSA-cj9f-h6r6-4cx2 (CVE-2026-27829), severity medium What it is: Astro is vulnerable to SSRF due to missing allowlist enforcement in remote image inferSize Affected packages: - @astrojs/node: affected versions >= 9.0.0, < 9.5.4. Fixed in 9.5.4. Details: https://github.com/advisories/GHSA-cj9f-h6r6-4cx2 Please: 1. Check package.json and the lockfile (package-lock.json, pnpm-lock.yaml, yarn.lock or bun.lock) for these packages, including copies pulled in by other dependencies, and tell me which versions are installed. 2. If none of them are installed, or every installed version is outside the affected ranges, say so and change nothing. 3. If an installed version is affected, upgrade it to the fixed version for its release line or later. When the package only comes in through another dependency, upgrade that dependency, or add an override or resolution if it has no fixed release yet. 4. If there is no fixed version, read the advisory and apply its workaround, or tell me the options. 5. Reinstall, run the build and the tests, and fix anything the upgrade breaks. 6. Tell me what you changed and which versions are installed now. - mediumFeb 23, 2026
Astro has Full-Read SSRF in error rendering via Host: header injection
- @astrojs/node < 9.5.4 · fixed in 9.5.4
GHSA-qq67-mvv5-fw3gCVE-2026-25545prompt for your AI agent
paste into your agentA security advisory covers a package this project may use. Advisory: GHSA-qq67-mvv5-fw3g (CVE-2026-25545), severity medium What it is: Astro has Full-Read SSRF in error rendering via Host: header injection Affected packages: - @astrojs/node: affected versions < 9.5.4. Fixed in 9.5.4. Details: https://github.com/advisories/GHSA-qq67-mvv5-fw3g Please: 1. Check package.json and the lockfile (package-lock.json, pnpm-lock.yaml, yarn.lock or bun.lock) for these packages, including copies pulled in by other dependencies, and tell me which versions are installed. 2. If none of them are installed, or every installed version is outside the affected ranges, say so and change nothing. 3. If an installed version is affected, upgrade it to the fixed version for its release line or later. When the package only comes in through another dependency, upgrade that dependency, or add an override or resolution if it has no fixed release yet. 4. If there is no fixed version, read the advisory and apply its workaround, or tell me the options. 5. Reinstall, run the build and the tests, and fix anything the upgrade breaks. 6. Tell me what you changed and which versions are installed now. - mediumDec 8, 2025
Astro has an Authentication Bypass via Double URL Encoding, a bypass for CVE-2025-64765
- astro < 5.15.8 · fixed in 5.15.8
GHSA-whqg-ppgf-wp8cCVE-2025-66202prompt for your AI agent
paste into your agentA security advisory covers a package this project may use. Advisory: GHSA-whqg-ppgf-wp8c (CVE-2025-66202), severity medium What it is: Astro has an Authentication Bypass via Double URL Encoding, a bypass for CVE-2025-64765 Affected packages: - astro: affected versions < 5.15.8. Fixed in 5.15.8. Details: https://github.com/advisories/GHSA-whqg-ppgf-wp8c Please: 1. Check package.json and the lockfile (package-lock.json, pnpm-lock.yaml, yarn.lock or bun.lock) for these packages, including copies pulled in by other dependencies, and tell me which versions are installed. 2. If none of them are installed, or every installed version is outside the affected ranges, say so and change nothing. 3. If an installed version is affected, upgrade it to the fixed version for its release line or later. When the package only comes in through another dependency, upgrade that dependency, or add an override or resolution if it has no fixed release yet. 4. If there is no fixed version, read the advisory and apply its workaround, or tell me the options. 5. Reinstall, run the build and the tests, and fix anything the upgrade breaks. 6. Tell me what you changed and which versions are installed now. - mediumNov 19, 2025
Astro Cloudflare adapter has Stored Cross-site Scripting vulnerability in /_image endpoint
- astro < 5.15.9 · fixed in 5.15.9
GHSA-fvmw-cj7j-j39qCVE-2025-65019prompt for your AI agent
paste into your agentA security advisory covers a package this project may use. Advisory: GHSA-fvmw-cj7j-j39q (CVE-2025-65019), severity medium What it is: Astro Cloudflare adapter has Stored Cross-site Scripting vulnerability in /_image endpoint Affected packages: - astro: affected versions < 5.15.9. Fixed in 5.15.9. Details: https://github.com/advisories/GHSA-fvmw-cj7j-j39q Please: 1. Check package.json and the lockfile (package-lock.json, pnpm-lock.yaml, yarn.lock or bun.lock) for these packages, including copies pulled in by other dependencies, and tell me which versions are installed. 2. If none of them are installed, or every installed version is outside the affected ranges, say so and change nothing. 3. If an installed version is affected, upgrade it to the fixed version for its release line or later. When the package only comes in through another dependency, upgrade that dependency, or add an override or resolution if it has no fixed release yet. 4. If there is no fixed version, read the advisory and apply its workaround, or tell me the options. 5. Reinstall, run the build and the tests, and fix anything the upgrade breaks. 6. Tell me what you changed and which versions are installed now. - mediumNov 19, 2025
Astro's middleware authentication checks based on url.pathname can be bypassed via url encoded values
- astro < 5.15.8 · fixed in 5.15.8
GHSA-ggxq-hp9w-j794CVE-2025-64765prompt for your AI agent
paste into your agentA security advisory covers a package this project may use. Advisory: GHSA-ggxq-hp9w-j794 (CVE-2025-64765), severity medium What it is: Astro's middleware authentication checks based on url.pathname can be bypassed via url encoded values Affected packages: - astro: affected versions < 5.15.8. Fixed in 5.15.8. Details: https://github.com/advisories/GHSA-ggxq-hp9w-j794 Please: 1. Check package.json and the lockfile (package-lock.json, pnpm-lock.yaml, yarn.lock or bun.lock) for these packages, including copies pulled in by other dependencies, and tell me which versions are installed. 2. If none of them are installed, or every installed version is outside the affected ranges, say so and change nothing. 3. If an installed version is affected, upgrade it to the fixed version for its release line or later. When the package only comes in through another dependency, upgrade that dependency, or add an override or resolution if it has no fixed release yet. 4. If there is no fixed version, read the advisory and apply its workaround, or tell me the options. 5. Reinstall, run the build and the tests, and fix anything the upgrade breaks. 6. Tell me what you changed and which versions are installed now. - highNov 19, 2025
Astro vulnerable to reflected XSS via the server islands feature
- astro <= 5.15.6 · fixed in 5.15.8
GHSA-wrwg-2hg8-v723CVE-2025-64764prompt for your AI agent
paste into your agentA security advisory covers a package this project may use. Advisory: GHSA-wrwg-2hg8-v723 (CVE-2025-64764), severity high What it is: Astro vulnerable to reflected XSS via the server islands feature Affected packages: - astro: affected versions <= 5.15.6. Fixed in 5.15.8. Details: https://github.com/advisories/GHSA-wrwg-2hg8-v723 Please: 1. Check package.json and the lockfile (package-lock.json, pnpm-lock.yaml, yarn.lock or bun.lock) for these packages, including copies pulled in by other dependencies, and tell me which versions are installed. 2. If none of them are installed, or every installed version is outside the affected ranges, say so and change nothing. 3. If an installed version is affected, upgrade it to the fixed version for its release line or later. When the package only comes in through another dependency, upgrade that dependency, or add an override or resolution if it has no fixed release yet. 4. If there is no fixed version, read the advisory and apply its workaround, or tell me the options. 5. Reinstall, run the build and the tests, and fix anything the upgrade breaks. 6. Tell me what you changed and which versions are installed now. - lowNov 19, 2025
Astro Development Server has Arbitrary Local File Read
- astro < 5.14.3 · fixed in 5.14.3
GHSA-x3h8-62x9-952gCVE-2025-64757prompt for your AI agent
paste into your agentA security advisory covers a package this project may use. Advisory: GHSA-x3h8-62x9-952g (CVE-2025-64757), severity low What it is: Astro Development Server has Arbitrary Local File Read Affected packages: - astro: affected versions < 5.14.3. Fixed in 5.14.3. Details: https://github.com/advisories/GHSA-x3h8-62x9-952g Please: 1. Check package.json and the lockfile (package-lock.json, pnpm-lock.yaml, yarn.lock or bun.lock) for these packages, including copies pulled in by other dependencies, and tell me which versions are installed. 2. If none of them are installed, or every installed version is outside the affected ranges, say so and change nothing. 3. If an installed version is affected, upgrade it to the fixed version for its release line or later. When the package only comes in through another dependency, upgrade that dependency, or add an override or resolution if it has no fixed release yet. 4. If there is no fixed version, read the advisory and apply its workaround, or tell me the options. 5. Reinstall, run the build and the tests, and fix anything the upgrade breaks. 6. Tell me what you changed and which versions are installed now. - mediumNov 13, 2025
Astro vulnerable to URL manipulation via headers, leading to middleware and CVE-2025-61925 bypass
- astro >= 2.16.0, < 5.15.5 · fixed in 5.15.5
GHSA-hr2q-hp5q-x767CVE-2025-64525prompt for your AI agent
paste into your agentA security advisory covers a package this project may use. Advisory: GHSA-hr2q-hp5q-x767 (CVE-2025-64525), severity medium What it is: Astro vulnerable to URL manipulation via headers, leading to middleware and CVE-2025-61925 bypass Affected packages: - astro: affected versions >= 2.16.0, < 5.15.5. Fixed in 5.15.5. Details: https://github.com/advisories/GHSA-hr2q-hp5q-x767 Please: 1. Check package.json and the lockfile (package-lock.json, pnpm-lock.yaml, yarn.lock or bun.lock) for these packages, including copies pulled in by other dependencies, and tell me which versions are installed. 2. If none of them are installed, or every installed version is outside the affected ranges, say so and change nothing. 3. If an installed version is affected, upgrade it to the fixed version for its release line or later. When the package only comes in through another dependency, upgrade that dependency, or add an override or resolution if it has no fixed release yet. 4. If there is no fixed version, read the advisory and apply its workaround, or tell me the options. 5. Reinstall, run the build and the tests, and fix anything the upgrade breaks. 6. Tell me what you changed and which versions are installed now. - lowNov 13, 2025
Astro development server error page is vulnerable to reflected Cross-site Scripting
- astro >= 5.2.0, < 5.15.6 · fixed in 5.15.6
GHSA-w2vj-39qv-7vh7CVE-2025-64745prompt for your AI agent
paste into your agentA security advisory covers a package this project may use. Advisory: GHSA-w2vj-39qv-7vh7 (CVE-2025-64745), severity low What it is: Astro development server error page is vulnerable to reflected Cross-site Scripting Affected packages: - astro: affected versions >= 5.2.0, < 5.15.6. Fixed in 5.15.6. Details: https://github.com/advisories/GHSA-w2vj-39qv-7vh7 Please: 1. Check package.json and the lockfile (package-lock.json, pnpm-lock.yaml, yarn.lock or bun.lock) for these packages, including copies pulled in by other dependencies, and tell me which versions are installed. 2. If none of them are installed, or every installed version is outside the affected ranges, say so and change nothing. 3. If an installed version is affected, upgrade it to the fixed version for its release line or later. When the package only comes in through another dependency, upgrade that dependency, or add an override or resolution if it has no fixed release yet. 4. If there is no fixed version, read the advisory and apply its workaround, or tell me the options. 5. Reinstall, run the build and the tests, and fix anything the upgrade breaks. 6. Tell me what you changed and which versions are installed now. - highOct 28, 2025
Astro's bypass of image proxy domain validation leads to SSRF and potential XSS
- astro >= 5.13.4, < 5.13.10 · fixed in 5.13.10
GHSA-qcpr-679q-rhm2CVE-2025-59837prompt for your AI agent
paste into your agentA security advisory covers a package this project may use. Advisory: GHSA-qcpr-679q-rhm2 (CVE-2025-59837), severity high What it is: Astro's bypass of image proxy domain validation leads to SSRF and potential XSS Affected packages: - astro: affected versions >= 5.13.4, < 5.13.10. Fixed in 5.13.10. Details: https://github.com/advisories/GHSA-qcpr-679q-rhm2 Please: 1. Check package.json and the lockfile (package-lock.json, pnpm-lock.yaml, yarn.lock or bun.lock) for these packages, including copies pulled in by other dependencies, and tell me which versions are installed. 2. If none of them are installed, or every installed version is outside the affected ranges, say so and change nothing. 3. If an installed version is affected, upgrade it to the fixed version for its release line or later. When the package only comes in through another dependency, upgrade that dependency, or add an override or resolution if it has no fixed release yet. 4. If there is no fixed version, read the advisory and apply its workaround, or tell me the options. 5. Reinstall, run the build and the tests, and fix anything the upgrade breaks. 6. Tell me what you changed and which versions are installed now. - mediumOct 10, 2025
Astro's `X-Forwarded-Host` is reflected without validation
- astro < 5.14.3 · fixed in 5.14.3
GHSA-5ff5-9fcw-vg88CVE-2025-61925prompt for your AI agent
paste into your agentA security advisory covers a package this project may use. Advisory: GHSA-5ff5-9fcw-vg88 (CVE-2025-61925), severity medium What it is: Astro's `X-Forwarded-Host` is reflected without validation Affected packages: - astro: affected versions < 5.14.3. Fixed in 5.14.3. Details: https://github.com/advisories/GHSA-5ff5-9fcw-vg88 Please: 1. Check package.json and the lockfile (package-lock.json, pnpm-lock.yaml, yarn.lock or bun.lock) for these packages, including copies pulled in by other dependencies, and tell me which versions are installed. 2. If none of them are installed, or every installed version is outside the affected ranges, say so and change nothing. 3. If an installed version is affected, upgrade it to the fixed version for its release line or later. When the package only comes in through another dependency, upgrade that dependency, or add an override or resolution if it has no fixed release yet. 4. If there is no fixed version, read the advisory and apply its workaround, or tell me the options. 5. Reinstall, run the build and the tests, and fix anything the upgrade breaks. 6. Tell me what you changed and which versions are installed now. - mediumAug 19, 2025
Astro allows unauthorized third-party images in _image endpoint
- @astrojs/node <= 9.1.0 · fixed in 9.1.1
- astro <= 4.16.18 · fixed in 4.16.19
- astro >= 5.0.0-alpha.0, < 5.13.2 · fixed in 5.13.2
GHSA-xf8x-j4p2-f749CVE-2025-55303prompt for your AI agent
paste into your agentA security advisory covers a package this project may use. Advisory: GHSA-xf8x-j4p2-f749 (CVE-2025-55303), severity medium What it is: Astro allows unauthorized third-party images in _image endpoint Affected packages: - @astrojs/node: affected versions <= 9.1.0. Fixed in 9.1.1. - astro: affected versions <= 4.16.18. Fixed in 4.16.19. - astro: affected versions >= 5.0.0-alpha.0, < 5.13.2. Fixed in 5.13.2. Details: https://github.com/advisories/GHSA-xf8x-j4p2-f749 Please: 1. Check package.json and the lockfile (package-lock.json, pnpm-lock.yaml, yarn.lock or bun.lock) for these packages, including copies pulled in by other dependencies, and tell me which versions are installed. 2. If none of them are installed, or every installed version is outside the affected ranges, say so and change nothing. 3. If an installed version is affected, upgrade it to the fixed version for its release line or later. When the package only comes in through another dependency, upgrade that dependency, or add an override or resolution if it has no fixed release yet. 4. If there is no fixed version, read the advisory and apply its workaround, or tell me the options. 5. Reinstall, run the build and the tests, and fix anything the upgrade breaks. 6. Tell me what you changed and which versions are installed now. - mediumAug 15, 2025
@astrojs/node's trailing slash handling causes open redirect issue
- @astrojs/node <= 9.4.0 · fixed in 9.4.1
GHSA-9x9c-ghc5-jhw9CVE-2025-55207prompt for your AI agent
paste into your agentA security advisory covers a package this project may use. Advisory: GHSA-9x9c-ghc5-jhw9 (CVE-2025-55207), severity medium What it is: @astrojs/node's trailing slash handling causes open redirect issue Affected packages: - @astrojs/node: affected versions <= 9.4.0. Fixed in 9.4.1. Details: https://github.com/advisories/GHSA-9x9c-ghc5-jhw9 Please: 1. Check package.json and the lockfile (package-lock.json, pnpm-lock.yaml, yarn.lock or bun.lock) for these packages, including copies pulled in by other dependencies, and tell me which versions are installed. 2. If none of them are installed, or every installed version is outside the affected ranges, say so and change nothing. 3. If an installed version is affected, upgrade it to the fixed version for its release line or later. When the package only comes in through another dependency, upgrade that dependency, or add an override or resolution if it has no fixed release yet. 4. If there is no fixed version, read the advisory and apply its workaround, or tell me the options. 5. Reinstall, run the build and the tests, and fix anything the upgrade breaks. 6. Tell me what you changed and which versions are installed now.
From the GitHub Advisory Database, refreshed hourly. Full history on GitHub.
Keeping Astro patched
npm audit(orpnpm audit) lists known vulnerable packages in your lockfile, including ones pulled in by other packages.- Turn on Dependabot for your GitHub repo and it opens the upgrade for you when an advisory lands.
- A patched framework doesn't cover your own setup: headers, cookies and HTTPS. The free check looks at those.