Skip to content

astro-5.18.1.tgz: 12 vulnerabilities (highest severity is: 8.3) #503

Description

@mend-bolt-for-github
Vulnerable Library - astro-5.18.1.tgz

Astro is a modern site builder with web best practices, performance, and DX front-of-mind.

Library home page: https://registry.npmjs.org/astro/-/astro-5.18.1.tgz

Path to dependency file: /package.json

Path to vulnerable library: /node_modules/astro/package.json

Found in HEAD commit: 37cad163797def09781066683d4aa4acf8c4d597

Vulnerabilities

Vulnerability Severity CVSS Dependency Type Fixed in (astro version) Remediation Possible**
CVE-2026-53632 High 8.3 vite-6.4.2.tgz Transitive N/A*
CVE-2026-59869 High 7.5 js-yaml-4.1.1.tgz Transitive N/A*
CVE-2026-54299 High 7.5 astro-5.18.1.tgz Direct https://github.com/withastro/astro.git - astro@6.4.6
CVE-2026-53571 High 7.5 vite-6.4.2.tgz Transitive N/A*
CVE-2026-42570 High 7.5 devalue-5.8.0.tgz Transitive N/A*
CVE-2026-50146 High 7.1 astro-5.18.1.tgz Direct https://github.com/withastro/astro.git - 6.3.3
CVE-2026-59729 Medium 6.1 astro-5.18.1.tgz Direct astro - 7.0.6
CVE-2026-59727 Medium 6.1 astro-5.18.1.tgz Direct astro - 7.0.4
CVE-2026-41067 Medium 6.1 astro-5.18.1.tgz Direct 6.1.6
CVE-2026-53550 Medium 5.3 js-yaml-4.1.1.tgz Transitive N/A*
CVE-2026-45028 Medium 5.3 astro-5.18.1.tgz Direct 6.1.10
CVE-2026-54298 Medium 4.2 astro-5.18.1.tgz Direct https://github.com/withastro/astro.git - 6.4.6

*For some transitive vulnerabilities, there is no version of direct dependency with a fix. Check the "Details" section below to see if there is a version of transitive dependency where vulnerability is fixed.

**In some cases, Remediation PR cannot be created automatically for a vulnerability despite the availability of remediation

Details

CVE-2026-53632

Vulnerable Library - vite-6.4.2.tgz

Native-ESM powered web dev build tool

Library home page: https://registry.npmjs.org/vite/-/vite-6.4.2.tgz

Path to dependency file: /package.json

Path to vulnerable library: /node_modules/vite/package.json

Dependency Hierarchy:

  • astro-5.18.1.tgz (Root Library)
    • vite-6.4.2.tgz (Vulnerable Library)

Found in HEAD commit: 37cad163797def09781066683d4aa4acf8c4d597

Found in base branch: main

Vulnerability Details

launch-editor allows users to open files with line numbers in editor from Node.js. Prior to 2.14.1, the launch-editor NPM package accesses arbitrary paths including Windows UNC paths. When a UNC path is opened, Windows automatically attempts NTLM authentication to the remote host, causing the user’s NTLMv2 password hash to be leaked to an attacker-controlled SMB server. This can result in credential compromise through offline hash cracking. This vulnerability is fixed in 2.14.1.

Publish Date: 2026-06-22

URL: CVE-2026-53632

CVSS 3 Score Details (8.3)

Base Score Metrics:

  • Exploitability Metrics:
    • Attack Vector: Network
    • Attack Complexity: High
    • Privileges Required: None
    • User Interaction: Required
    • Scope: Changed
  • Impact Metrics:
    • Confidentiality Impact: High
    • Integrity Impact: High
    • Availability Impact: High

For more information on CVSS3 Scores, click here.

Suggested Fix

Type: Upgrade version

Release Date: 2026-06-15

Fix Resolution: https://github.com/vitejs/vite.git - v8.0.16,https://github.com/vitejs/vite.git - v6.4.3,https://github.com/vitejs/launch-editor.git - v2.14.1,https://github.com/vitejs/vite.git - v7.3.5

Step up your Open Source Security Game with Mend here

CVE-2026-59869

Vulnerable Library - js-yaml-4.1.1.tgz

YAML 1.2 parser and serializer

Library home page: https://registry.npmjs.org/js-yaml/-/js-yaml-4.1.1.tgz

Path to dependency file: /package.json

Path to vulnerable library: /node_modules/js-yaml/package.json

Dependency Hierarchy:

  • astro-5.18.1.tgz (Root Library)
    • js-yaml-4.1.1.tgz (Vulnerable Library)

Found in HEAD commit: 37cad163797def09781066683d4aa4acf8c4d597

Found in base branch: main

Vulnerability Details

js-yaml is a JavaScript YAML parser and dumper. From 3.0.0 before 3.15.0 and from 4.0.0 before 4.3.0, js-yaml can spend quadratic CPU time parsing a document whose size grows only linearly when a chain of mappings uses merge keys where each mapping merges the previous one. This issue is fixed in versions 3.15.0 and 4.3.0.

Publish Date: 2026-07-08

URL: CVE-2026-59869

CVSS 3 Score Details (7.5)

Base Score Metrics:

  • Exploitability Metrics:
    • Attack Vector: Network
    • Attack Complexity: Low
    • Privileges Required: None
    • User Interaction: None
    • Scope: Unchanged
  • Impact Metrics:
    • Confidentiality Impact: None
    • Integrity Impact: None
    • Availability Impact: High

For more information on CVSS3 Scores, click here.

Suggested Fix

Type: Upgrade version

Release Date: 2026-07-08

Fix Resolution: https://github.com/nodeca/js-yaml.git - 3.15.0,https://github.com/nodeca/js-yaml.git - 4.3.0,js-yaml - 4.3.0,js-yaml - 3.15.0,js-yaml - 4.3.0,js-yaml - 3.15.0

Step up your Open Source Security Game with Mend here

CVE-2026-54299

Vulnerable Library - astro-5.18.1.tgz

Astro is a modern site builder with web best practices, performance, and DX front-of-mind.

Library home page: https://registry.npmjs.org/astro/-/astro-5.18.1.tgz

Path to dependency file: /package.json

Path to vulnerable library: /node_modules/astro/package.json

Dependency Hierarchy:

  • astro-5.18.1.tgz (Vulnerable Library)

Found in HEAD commit: 37cad163797def09781066683d4aa4acf8c4d597

Found in base branch: main

Vulnerability Details

Astro is a web framework. Prior to 6.4.6, Astro SSR apps with prerendered error pages (/404 or /500 using export const prerender = true) fetch those pages over HTTP at runtime when an error occurs. The URL for this fetch is derived from request.url, which in turn gets its origin from the incoming Host header. When the Host header is not validated against allowedDomains, an attacker can point the fetch at an arbitrary host and read the response. This vulnerability is fixed in 6.4.6.

Publish Date: 2026-06-22

URL: CVE-2026-54299

CVSS 3 Score Details (7.5)

Base Score Metrics:

  • Exploitability Metrics:
    • Attack Vector: Network
    • Attack Complexity: High
    • Privileges Required: None
    • User Interaction: None
    • Scope: Changed
  • Impact Metrics:
    • Confidentiality Impact: High
    • Integrity Impact: Low
    • Availability Impact: None

For more information on CVSS3 Scores, click here.

Suggested Fix

Type: Upgrade version

Release Date: 2026-06-16

Fix Resolution: https://github.com/withastro/astro.git - astro@6.4.6

Step up your Open Source Security Game with Mend here

CVE-2026-53571

Vulnerable Library - vite-6.4.2.tgz

Native-ESM powered web dev build tool

Library home page: https://registry.npmjs.org/vite/-/vite-6.4.2.tgz

Path to dependency file: /package.json

Path to vulnerable library: /node_modules/vite/package.json

Dependency Hierarchy:

  • astro-5.18.1.tgz (Root Library)
    • vite-6.4.2.tgz (Vulnerable Library)

Found in HEAD commit: 37cad163797def09781066683d4aa4acf8c4d597

Found in base branch: main

Vulnerability Details

Vite is a frontend tooling framework for JavaScript. Prior to 8.0.16, 7.3.5, and 6.4.3, the contents of files that are specified by server.fs.deny can be returned to the browser on Windows. Vite’s dev server denies direct access to sensitive files through server.fs.deny, including entries such as .env, .env.*, and *.{crt,pem}. However, on Windows, the deny logic does not correctly normalize NTFS ADS path forms before access checks are applied. Because of this, requests such as /.env::$DATA?raw are treated as allowed paths, while Windows resolves them to the original file's default data stream. Similar to that, Windows allows accessing a file using a different name with the 8.3 short name compatibility feature. Vite did not reject accessing files via them. This vulnerability is fixed in 8.0.16, 7.3.5, and 6.4.3.

Publish Date: 2026-06-22

URL: CVE-2026-53571

CVSS 3 Score Details (7.5)

Base Score Metrics:

  • Exploitability Metrics:
    • Attack Vector: Network
    • Attack Complexity: Low
    • Privileges Required: None
    • User Interaction: None
    • Scope: Unchanged
  • Impact Metrics:
    • Confidentiality Impact: High
    • Integrity Impact: None
    • Availability Impact: None

For more information on CVSS3 Scores, click here.

Suggested Fix

Type: Upgrade version

Release Date: 2026-06-15

Fix Resolution: https://github.com/vitejs/vite.git - v6.4.3,https://github.com/vitejs/vite.git - v8.0.16,https://github.com/vitejs/vite.git - v7.3.5

Step up your Open Source Security Game with Mend here

CVE-2026-42570

Vulnerable Library - devalue-5.8.0.tgz

Gets the job done when JSON.stringify can't

Library home page: https://registry.npmjs.org/devalue/-/devalue-5.8.0.tgz

Path to dependency file: /package.json

Path to vulnerable library: /node_modules/devalue/package.json

Dependency Hierarchy:

  • astro-5.18.1.tgz (Root Library)
    • devalue-5.8.0.tgz (Vulnerable Library)

Found in HEAD commit: 37cad163797def09781066683d4aa4acf8c4d597

Found in base branch: main

Vulnerability Details

Svelte devalue is a JavaScript library that serializes values into strings when JSON.stringify isn't sufficient for the job. From version 5.6.3 to before version 5.8.1, devalue.parse could, due to quirks in some JavaScript engines, be convinced to allocate much more memory than was needed when deserializing sparse arrays, leading to excessive memory consumption. This issue has been patched in version 5.8.1.

Publish Date: 2026-06-09

URL: CVE-2026-42570

CVSS 3 Score Details (7.5)

Base Score Metrics:

  • Exploitability Metrics:
    • Attack Vector: Network
    • Attack Complexity: Low
    • Privileges Required: None
    • User Interaction: None
    • Scope: Unchanged
  • Impact Metrics:
    • Confidentiality Impact: None
    • Integrity Impact: None
    • Availability Impact: High

For more information on CVSS3 Scores, click here.

Suggested Fix

Type: Upgrade version

Release Date: 2026-05-16

Fix Resolution: https://github.com/sveltejs/devalue.git - v5.8.1

Step up your Open Source Security Game with Mend here

CVE-2026-50146

Vulnerable Library - astro-5.18.1.tgz

Astro is a modern site builder with web best practices, performance, and DX front-of-mind.

Library home page: https://registry.npmjs.org/astro/-/astro-5.18.1.tgz

Path to dependency file: /package.json

Path to vulnerable library: /node_modules/astro/package.json

Dependency Hierarchy:

  • astro-5.18.1.tgz (Vulnerable Library)

Found in HEAD commit: 37cad163797def09781066683d4aa4acf8c4d597

Found in base branch: main

Vulnerability Details

Astro is a web framework. Prior to 6.3.3, when a component uses a client:* directive, Astro inserts named slot content into a data-astro-template attribute without HTML escaping the slot name allowing an attacker to break out of the attribute context and inject arbitrary HTML, resulting in reflected XSS during SSR. This vulnerability is fixed in 6.3.3.

Publish Date: 2026-06-22

URL: CVE-2026-50146

CVSS 3 Score Details (7.1)

Base Score Metrics:

  • Exploitability Metrics:
    • Attack Vector: Network
    • Attack Complexity: Low
    • Privileges Required: None
    • User Interaction: Required
    • Scope: Unchanged
  • Impact Metrics:
    • Confidentiality Impact: Low
    • Integrity Impact: High
    • Availability Impact: None

For more information on CVSS3 Scores, click here.

Suggested Fix

Type: Upgrade version

Release Date: 2026-06-16

Fix Resolution: https://github.com/withastro/astro.git - 6.3.3

Step up your Open Source Security Game with Mend here

CVE-2026-59729

Vulnerable Library - astro-5.18.1.tgz

Astro is a modern site builder with web best practices, performance, and DX front-of-mind.

Library home page: https://registry.npmjs.org/astro/-/astro-5.18.1.tgz

Path to dependency file: /package.json

Path to vulnerable library: /node_modules/astro/package.json

Dependency Hierarchy:

  • astro-5.18.1.tgz (Vulnerable Library)

Found in HEAD commit: 37cad163797def09781066683d4aa4acf8c4d597

Found in base branch: main

Vulnerability Details

Summary The fix for CVE-2026-54298 (GHSA-jrpj-wcv7-9fh9) added an "INVALID_ATTR_NAME_CHAR" guard to "addAttribute()" so that spread-prop attribute names containing ""' >/=" or whitespace are dropped. A second attribute-rendering path, "renderHTMLElement()" in "packages/astro/src/runtime/server/render/dom.ts", has its own inline attribute loop that does not go through "addAttribute()" and was not updated. It interpolates the attribute name unescaped and only escapes the value, so untrusted prop keys spread onto a native-"HTMLElement"-subclass component can still break out of the attribute context, resulting in XSS. Details "renderHTMLElement" builds attributes directly: for (const attr in props) { attrHTML += " ${attr}="${toAttributeString(await props[attr])}""; } The attribute name ("attr") is interpolated raw; only the value is escaped via "toAttributeString". By contrast, the hardened "addAttribute" in "util.ts" rejects invalid names: if (INVALID_ATTR_NAME_CHAR.test(key)) { return ''; } // /[\s"'>/=]/ "renderHTMLElement" is reached from "component.ts" when the component is a native "HTMLElement" subclass: if (!renderer && typeof HTMLElement === 'function' && componentIsHTMLElement(Component)) { const output = await renderHTMLElement(result, Component, _props, slots); } where "_props" carries spread props verbatim. Reachability The branch only runs when "typeof HTMLElement === 'function'" at SSR time. In default Node SSR "HTMLElement" is "undefined", so the branch is dead. It becomes reachable when the SSR runtime exposes a global "HTMLElement" (Deno, Bun with a DOM shim, or jsdom/happy-dom in Node) and a class extending "HTMLElement" is used directly as an Astro component that receives untrusted-keyed spread props. Proof of Concept Given malicious spread props: const maliciousProps = { 'onmouseover=alert(document.domain) x': 'y', 'x><script>alert(1)</script>': 'z', }; - "addAttribute" (post-fix) → "" (key stripped — safe) - "renderHTMLElement" → "<script>alert(1)</script>="z">" (handler + "<script>" injected — XSS) Equivalent Astro template, served by an SSR runtime that defines a global "HTMLElement": import MyElement from '../MyElement.js'; // class MyElement extends HTMLElement {} const userInput = Astro.url.searchParams; // untrusted keys <MyElement {...Object.fromEntries(userInput)} /> Impact Cross-site scripting (CWE-79) via attribute-name breakout — the same vulnerability class as CVE-2026-54298, in a code path its fix did not cover. An attacker who controls the keys of an object spread onto a native-"HTMLElement"-subclass component can inject arbitrary event-handler attributes or sibling elements (including "<script>") into the SSR output. Reachability is constrained by the runtime and component preconditions described above.

Publish Date: 2026-07-21

URL: CVE-2026-59729

CVSS 3 Score Details (6.1)

Base Score Metrics:

  • Exploitability Metrics:
    • Attack Vector: Network
    • Attack Complexity: Low
    • Privileges Required: None
    • User Interaction: Required
    • Scope: Changed
  • Impact Metrics:
    • Confidentiality Impact: Low
    • Integrity Impact: Low
    • Availability Impact: None

For more information on CVSS3 Scores, click here.

Suggested Fix

Type: Upgrade version

Origin: GHSA-f48w-9m4c-m7f5

Release Date: 2026-07-21

Fix Resolution: astro - 7.0.6

Step up your Open Source Security Game with Mend here

CVE-2026-59727

Vulnerable Library - astro-5.18.1.tgz

Astro is a modern site builder with web best practices, performance, and DX front-of-mind.

Library home page: https://registry.npmjs.org/astro/-/astro-5.18.1.tgz

Path to dependency file: /package.json

Path to vulnerable library: /node_modules/astro/package.json

Dependency Hierarchy:

  • astro-5.18.1.tgz (Vulnerable Library)

Found in HEAD commit: 37cad163797def09781066683d4aa4acf8c4d597

Found in base branch: main

Vulnerability Details

Summary When a "transition:persist", "transition:scope", or "transition:persist-props" directive is applied to a client-hydrated ("client:*") component, Astro copied the directive value onto the rendered "" element without HTML-escaping it. If a developer reflects attacker-controlled input into one of these directives, an attacker can break out of the attribute and inject arbitrary HTML/JavaScript into the server-rendered output, resulting in reflected cross-site scripting (XSS). Severity Although a generic reflected XSS scores in the Medium range, exploitation here requires the application developer to have written a non-idiomatic pattern — passing untrusted, request-derived input directly into a transition directive. Astro applications that do not route untrusted input into these directives are unaffected. This mitigating precondition places the real-world severity at Low. Details In "generateHydrateScript()" ("packages/astro/src/runtime/server/hydration.ts"), every island property is HTML-escaped before serialization — the "attrs", "props", and "opts" assignments all pass through "escapeHTML()". The transition directives, however, were copied verbatim: transitionDirectivesToCopyOnIsland.forEach((name) => { if (typeof props[name] !== 'undefined') { island.props[name] = props[name]; // not escaped } }); The "" element is serialized via "renderElement('astro-island', island, false)" with "shouldEscape=false", and "toAttributeString()" returns the value unchanged in that mode. As a result there is no downstream re-escaping, and the raw directive value reaches the HTML response. This is the same output sink previously addressed for slot names in GHSA-8hv8-536x-4wqp. The affected directives are: - "data-astro-transition-scope" ("transition:scope") - "data-astro-transition-persist" ("transition:persist") - "data-astro-transition-persist-props" ("transition:persist-props") Note that "transition:persist" is typed "boolean | string", so passing a string value is a supported use of the API. Proof of Concept A component that reflects a query parameter into a transition directive: const persist = Astro.url.searchParams.get('persist') ?? 'default'; Request: https://example.com/?persist="> Rendered output (before the fix): <astro-island … data-astro-transition-persist="">> The """ closes the attribute and the injected "" executes in the victim's browser. Impact Reflected XSS. An attacker who can induce a victim to visit a crafted URL can execute arbitrary script in the victim's session on the origin, subject to the requirement that the target application reflects untrusted input into one of the affected transition directives. Affected Versions "astro >= 3.10.0, < 7.0.4" (introduced in 3.10.0, PR #⁠7861). Patched Versions "astro >= 7.0.4". Fixed in PR #⁠17212 by HTML-escaping transition directive values before they are rendered onto the island element. Workarounds Do not pass untrusted or request-derived input into "transition:persist", "transition:scope", or "transition:persist-props". If such input is required, HTML-escape or strictly validate it before passing it to the directive. Upgrading to "astro@7.0.4" or later removes the need for manual mitigation. Credits Reported by @⁠jlgore.

Publish Date: 2026-07-21

URL: CVE-2026-59727

CVSS 3 Score Details (6.1)

Base Score Metrics:

  • Exploitability Metrics:
    • Attack Vector: Network
    • Attack Complexity: Low
    • Privileges Required: None
    • User Interaction: Required
    • Scope: Changed
  • Impact Metrics:
    • Confidentiality Impact: Low
    • Integrity Impact: Low
    • Availability Impact: None

For more information on CVSS3 Scores, click here.

Suggested Fix

Type: Upgrade version

Origin: GHSA-7pw4-f3q4-r2p2

Release Date: 2026-07-21

Fix Resolution: astro - 7.0.4

Step up your Open Source Security Game with Mend here

CVE-2026-41067

Vulnerable Library - astro-5.18.1.tgz

Astro is a modern site builder with web best practices, performance, and DX front-of-mind.

Library home page: https://registry.npmjs.org/astro/-/astro-5.18.1.tgz

Path to dependency file: /package.json

Path to vulnerable library: /node_modules/astro/package.json

Dependency Hierarchy:

  • astro-5.18.1.tgz (Vulnerable Library)

Found in HEAD commit: 37cad163797def09781066683d4aa4acf8c4d597

Found in base branch: main

Vulnerability Details

Astro is a web framework. Prior to 6.1.6, the defineScriptVars function in Astro's server-side rendering pipeline uses a case-sensitive regex /</script>/g to sanitize values injected into inline <script> tags via the define:vars directive. HTML parsers close <script> elements case-insensitively and also accept whitespace or / before the closing >, allowing an attacker to bypass the sanitization with payloads like </Script>, </script >, or </script/> and inject arbitrary HTML/JavaScript. This vulnerability is fixed in 6.1.6.
Mend Note: The description of this vulnerability differs from MITRE.

Publish Date: 2026-04-24

URL: CVE-2026-41067

CVSS 3 Score Details (6.1)

Base Score Metrics:

  • Exploitability Metrics:
    • Attack Vector: Network
    • Attack Complexity: Low
    • Privileges Required: None
    • User Interaction: Required
    • Scope: Changed
  • Impact Metrics:
    • Confidentiality Impact: Low
    • Integrity Impact: Low
    • Availability Impact: None

For more information on CVSS3 Scores, click here.

Suggested Fix

Type: Upgrade version

Origin: GHSA-j687-52p2-xcff

Release Date: 2026-04-24

Fix Resolution: 6.1.6

Step up your Open Source Security Game with Mend here

CVE-2026-53550

Vulnerable Library - js-yaml-4.1.1.tgz

YAML 1.2 parser and serializer

Library home page: https://registry.npmjs.org/js-yaml/-/js-yaml-4.1.1.tgz

Path to dependency file: /package.json

Path to vulnerable library: /node_modules/js-yaml/package.json

Dependency Hierarchy:

  • astro-5.18.1.tgz (Root Library)
    • js-yaml-4.1.1.tgz (Vulnerable Library)

Found in HEAD commit: 37cad163797def09781066683d4aa4acf8c4d597

Found in base branch: main

Vulnerability Details

js-yaml is a JavaScript YAML parser and dumper. Prior to 4.2.0 and 3.15.0, a crafted YAML document can trigger algorithmic CPU exhaustion in js-yaml merge-key processing (<<) by repeating the same alias many times in a merge sequence. This causes quadratic parse-time behavior relative to input size and can block a Node.js worker/event loop for seconds with a relatively small payload (tens of KB), resulting in denial of service. The issue is in merge handling inside lib/loader.js. This vulnerability is fixed in 4.2.0 and 3.15.0.

Publish Date: 2026-06-22

URL: CVE-2026-53550

CVSS 3 Score Details (5.3)

Base Score Metrics:

  • Exploitability Metrics:
    • Attack Vector: Network
    • Attack Complexity: Low
    • Privileges Required: None
    • User Interaction: None
    • Scope: Unchanged
  • Impact Metrics:
    • Confidentiality Impact: None
    • Integrity Impact: None
    • Availability Impact: Low

For more information on CVSS3 Scores, click here.

Suggested Fix

Type: Upgrade version

Release Date: 2026-06-15

Fix Resolution: https://github.com/nodeca/js-yaml.git - 4.2.0

Step up your Open Source Security Game with Mend here

CVE-2026-45028

Vulnerable Library - astro-5.18.1.tgz

Astro is a modern site builder with web best practices, performance, and DX front-of-mind.

Library home page: https://registry.npmjs.org/astro/-/astro-5.18.1.tgz

Path to dependency file: /package.json

Path to vulnerable library: /node_modules/astro/package.json

Dependency Hierarchy:

  • astro-5.18.1.tgz (Vulnerable Library)

Found in HEAD commit: 37cad163797def09781066683d4aa4acf8c4d597

Found in base branch: main

Vulnerability Details

Astro is a web framework. Astro versions prior to 6.1.10 used AES-GCM encryption to protect the confidentiality and integrity of server island props and slots parameters, but did not bind the ciphertext to its intended component or parameter type. An attacker could replay one component's encrypted props (p) value as another component's slots (s) value, or vice versa. Since slots contain raw unescaped HTML while props may contain user-controlled values, this could lead to XSS in applications. This occurs when the application uses server islands, two different server island components share the same key name for a prop and a slot, and an attacker has full control over the value of the overlapping prop (requires a dynamically rendered page). This vulnerability is fixed in 6.1.10.

Publish Date: 2026-05-13

URL: CVE-2026-45028

CVSS 3 Score Details (5.3)

Base Score Metrics:

  • Exploitability Metrics:
    • Attack Vector: Network
    • Attack Complexity: Low
    • Privileges Required: None
    • User Interaction: None
    • Scope: Unchanged
  • Impact Metrics:
    • Confidentiality Impact: None
    • Integrity Impact: Low
    • Availability Impact: None

For more information on CVSS3 Scores, click here.

Suggested Fix

Type: Upgrade version

Release Date: 2026-05-14

Fix Resolution: 6.1.10

Step up your Open Source Security Game with Mend here

CVE-2026-54298

Vulnerable Library - astro-5.18.1.tgz

Astro is a modern site builder with web best practices, performance, and DX front-of-mind.

Library home page: https://registry.npmjs.org/astro/-/astro-5.18.1.tgz

Path to dependency file: /package.json

Path to vulnerable library: /node_modules/astro/package.json

Dependency Hierarchy:

  • astro-5.18.1.tgz (Vulnerable Library)

Found in HEAD commit: 37cad163797def09781066683d4aa4acf8c4d597

Found in base branch: main

Vulnerability Details

Astro is a web framework. Prior to 6.4.6, the spreadAttributes function in Astro's server-side rendering pipeline iterates over object keys and passes them directly to addAttribute, which interpolates the key into the HTML output without escaping. When a developer uses the spread syntax {...props} on an HTML element and the object keys come from an untrusted source (API, CMS, URL parameters), an attacker can inject arbitrary HTML attributes including event handlers like onmousemove, onclick, or break out of the attribute context entirely to inject new elements. This vulnerability is fixed in 6.4.6.

Publish Date: 2026-06-22

URL: CVE-2026-54298

CVSS 3 Score Details (4.2)

Base Score Metrics:

  • Exploitability Metrics:
    • Attack Vector: Network
    • Attack Complexity: High
    • Privileges Required: None
    • User Interaction: Required
    • Scope: Unchanged
  • Impact Metrics:
    • Confidentiality Impact: Low
    • Integrity Impact: Low
    • Availability Impact: None

For more information on CVSS3 Scores, click here.

Suggested Fix

Type: Upgrade version

Origin: GHSA-jrpj-wcv7-9fh9

Release Date: 2026-06-16

Fix Resolution: https://github.com/withastro/astro.git - 6.4.6

Step up your Open Source Security Game with Mend here

Metadata

Metadata

Assignees

No one assigned

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions