Executive brief
The @astrojs/netlify adapter, which helps deploy Astro websites to the Netlify platform, contains a flaw in how it handles image security rules. When developers specify which external images are allowed to be optimized by the Netlify Image CDN, the system fails to properly secure the pathnames. This could allow the CDN to process and serve unintended images from an already-approved host, potentially leading to unauthorized content being cached or optimized.
Technical details
The vulnerability exists in the `remotePatternToRegex()` function within `packages/integrations/netlify/src/index.ts`. While the function correctly escapes dots in the hostname, it interpolates the `pathname` into the final regular expression without escaping regex metacharacters (such as '.', '+', or '?'). Because Netlify's Image CDN uses these generated regexes directly for its allowlist, an attacker can bypass intended path restrictions. For example, a dot in a version segment or file extension will match any character, including directory separators, widening the scope of allowed remote images beyond what the developer defined. This is a residual issue following a previous fix for wildcard semantics. The issue is resolved in version 8.1.2.
Affected products
- Astro @astrojs/netlify < 8.1.2
Timeline
- 2026-07-15: disclosed
- 2026-07-20: advisory: GHSA-hp3v-mfqw-h74c published
- 2026-07-20: patched: Version 8.1.2 released