Junglewise Threat Intelligence

CVE-2026-45028: Astro cross-component replay in server islands

CVE-2026-45028 · Severity: medium · CVSS 6.1 · Published 2026-05-13

Technologies: astro (npm). Vendors: npm.

Executive brief

Astro is a popular web framework used to build fast, content-focused websites. A vulnerability in its "server islands" feature could allow an attacker to manipulate how data is displayed on a page, potentially leading to malicious scripts being executed in a user's browser. While this could lead to unauthorized actions or data theft, the specific conditions required for a successful attack are rare in typical production environments.

Technical details

Astro versions prior to 6.1.10 used AES-GCM to encrypt server island parameters (props and slots) but failed to bind the ciphertext to a specific component or parameter type. This lack of cryptographic binding allows an attacker to perform a replay attack, taking an encrypted 'props' value (which may contain user-controlled data) and submitting it as a 'slots' value. Because slots are rendered as raw, unescaped HTML, this can result in Cross-Site Scripting (XSS) if a prop and slot share the same key name across different components. The fix introduces Authenticated Additional Data (AAD) to the AES-GCM process, binding the ciphertext to the specific component name and parameter type.

Affected products

  • withastro astro < 6.1.10

Timeline

  • 2026-05-07: patched: Fix published in version 6.1.10
  • 2026-05-13: disclosed: GitHub Advisory published

References

Related threats