Executive brief
Astro is a web framework used to build fast, content-focused websites. The server islands feature allows dynamic server-rendered components, but contains an XSS vulnerability that allows attackers to inject malicious scripts through URL parameters. An attacker can craft a special URL that, when clicked by a user, executes arbitrary JavaScript in the victim's browser, potentially stealing session cookies, credentials, or performing actions on behalf of the user.
Technical details
The vulnerability is a reflected cross-site scripting (XSS) flaw in Astro's server islands feature. The `/_server-islands/[name]` endpoint accepts three parameters: `e` (component export), `p` (properties), and `s` (slots). When the `e` parameter is set to "file", the endpoint generates an HTML template using the island's absolute file path as an HTML tag name and injects the `s` parameter value directly as child content using `markHTMLString` without proper sanitization. This allows an unauthenticated attacker to inject arbitrary HTML/JavaScript via the `s` parameter in a URL. The attack requires user interaction (clicking a malicious link) but works regardless of the actual component template design. The vulnerability affects all versions up to 5.15.6 and is patched in version 5.15.8.
Affected products
- Astro Astro <= 5.15.6
Timeline
- 2025-11-19: disclosed
- 2025-11-19: patched: Fixed in version 5.15.8