Executive brief
Astro's Vercel adapter with ISR (Incremental Static Regeneration) enabled allows unauthenticated users to bypass edge-level access controls by specifying arbitrary page paths via a query parameter. An attacker can read any protected page or API response that is secured only at the edge (e.g., through Vercel firewall rules or edge middleware), compromising the confidentiality of sensitive content and potentially exposing administrative interfaces.
Technical details
The @astrojs/vercel serverless entrypoint reads the x_astro_path query parameter (via ISR) and the x-astro-path header to override the internal request path without authentication. While the header path is protected by a per-build middleware secret, the ISR query parameter path is guarded only by the x-vercel-isr header, which Vercel sets on all requests including direct external ones—meaning any caller can supply x_astro_path. This creates a confused deputy problem: edge firewalls and path-based rules see only the /_isr path (allowed), while the origin renders the attacker-controlled path. In split deployments with edge middleware, the middleware runs only against /_isr and never reaches the origin, so authorization is completely bypassed. The vulnerability is reachable via GET requests only (POST/PUT/DELETE are blocked by Vercel's ISR layer), limiting impact to confidentiality. The issue was introduced in version 10.0.3 when a fix for a prior path override vulnerability was weakened. A patch is available in @astrojs/vercel 11.0.3 and later.
Affected products
- Astro Vercel adapter 10.0.3 to 11.0.2
Timeline
- 2026-07-20: disclosed: GHSA-x27w-589x-frm2 published
- 2026-07-20: patched: @astrojs/vercel 11.0.3 released with fix