Junglewise Threat Intelligence

CVE-2026-50146: withastro Astro reflected XSS in data-astro-template attribute

CVE-2026-50146 · Severity: high · CVSS 7.1 · Published 2026-06-22

Technologies: astro (npm). Vendors: npm.

Executive brief

Astro is a web framework used to build fast, content-driven websites. A security flaw in how the framework handles component templates allows attackers to inject malicious scripts into a website if the site uses dynamic slot names based on user input. This could lead to unauthorized actions being performed in a user's browser, such as stealing session information or defacing the site's content.

Technical details

A reflected Cross-Site Scripting (XSS) vulnerability exists in Astro's Server-Side Rendering (SSR) engine. When a component utilizes a 'client:*' directive, the framework generates a 'data-astro-template' attribute. The 'key' representing the slot name is interpolated directly into this attribute without proper HTML escaping in 'packages/astro/src/runtime/server/render/component.ts'. An attacker can provide a crafted slot name (e.g., via URL parameters) containing quotes and HTML tags to break out of the attribute context and execute arbitrary JavaScript in the victim's browser. This issue is fixed in version 6.3.3 by applying HTML escaping to the slot name.

Affected products

  • withastro Astro < 6.3.3

Timeline

  • 2026-06-12: advisory: GitHub Security Advisory published by maintainers
  • 2026-06-22: disclosed: CVE published to NVD
  • 2026-06-22: patched: Fix confirmed in version 6.3.3

References

Related threats