Junglewise Threat Intelligence

CVE-2026-41067: Astro: XSS in define:vars via incomplete </script> tag sanitization

CVE-2026-41067 · Severity: medium · CVSS 6.1 · Published 2026-04-21

Technologies: astro (npm). Vendors: Astro, npm.

Executive brief

Astro is a web framework that allows developers to pass variables into inline script tags via the define:vars directive. A flaw in the sanitization logic fails to block certain HTML-valid variations of closing script tags (case variations, whitespace, slashes), allowing attackers to inject arbitrary JavaScript that executes in users' browsers. This enables session hijacking, credential theft, and malware injection on affected applications that use SSR with user-controlled input.

Technical details

The vulnerability is a cross-site scripting (XSS) flaw in the defineScriptVars function in packages/astro/src/runtime/server/render/util.ts. The function uses a case-sensitive regex pattern (/&lt;\/script&gt;/g) to sanitize values injected into script tags, but HTML parsers accept closing script tags case-insensitively and with whitespace or forward slashes before the closing bracket (e.g., &lt;/Script&gt;, &lt;/script &gt;, &lt;/script/&gt;). An attacker can bypass sanitization by crafting payloads using these variations, break out of the script context, and inject arbitrary HTML/JavaScript. The attack requires SSR to be enabled and user input to be passed through define:vars on a script element—a documented usage pattern. Fixes are available in Astro 6.1.6; the recommended patch escapes all &lt; characters using \u003c to prevent all closing tag variants.

Affected products

  • Astro Astro &lt;= 6.1.1

Timeline

  • 2026-04-21: disclosed: GHSA-j687-52p2-xcff published
  • 2026-04-21: patched: Fix released in Astro 6.1.6

References

Related threats