Executive brief
Astro's Vercel integration contains an authentication bypass vulnerability in its serverless deployment layer. Attackers can manipulate HTTP request paths using headers or query parameters to bypass Vercel's firewall rules and access protected pages and APIs without authorization. This affects deployments without Edge Middleware, allowing unauthorized read and write access to restricted endpoints.
Technical details
The @astrojs/vercel serverless entrypoint reads the x-astro-path header and x_astro_path query parameter to rewrite request paths without any authentication or validation. While this mechanism is intended for legitimate use by Edge Middleware (which overwrites client-supplied values), deployments without Edge Middleware expose this path-rewriting to external callers. An attacker can craft requests to /public?x_astro_path=/admin/secret to bypass Vercel's platform-level firewall rules; the firewall evaluates the public path while the serverless function executes the admin path. The HTTP method and body are preserved through the override, affecting GET, POST, PUT, and DELETE requests. Affected versions include @astrojs/vercel ≤ 10.0.0; the vulnerability is confirmed exploitable on Astro 5.18.1 + @astrojs/vercel 9.0.4. Patch version 10.0.2 is available.
Affected products
- Astro @astrojs/vercel <= 10.0.0
Timeline
- 2026-03-26: disclosed
- 2026-03-26: patched: Patched in @astrojs/vercel 10.0.2