Technology · npm
astro (npm) vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 30 vulnerabilities in astro (npm): 0 in the last 7 days and 11 in the last 90 days, 1 of them critical and 0 exploited in the wild. The most recent, Astro remote code execution via AVIF image processing, was published on 8 September 2026.
- Last 7 days
- 0
- Last 90 days
- 11
- Critical, all time
- 1
- Exploited in the wild
- 0
About astro (npm)
A web framework for building content-driven websites with a focus on performance and minimal client-side JavaScript.
Latest astro (npm) vulnerabilities
- Astro remote code execution via AVIF image processinglowCVSS 3.1
- Astro remote code execution through AVIF image optimizationcriticalCVSS 9.8
- CVE-2026-84376: Astro is a web framework for content-driven websites. Prior to 7.2.4, Astro stripped a configured non-root base path from…mediumCVSS 4EPSS 0.7%
- CVE-2026-73423: Astro is a web framework for content-driven websites. From 7.0.0 until 7.0.6, the composable astro/hono pipeline installs…mediumCVSS 4EPSS 0.3%
- CVE-2026-73422: Astro is a web framework for content-driven websites. From 2.9.0 until 7.1.0, Astro's server-side View Transition CSS…mediumCVSS 4EPSS 0.5%
- CVE-2026-59730: withastro Astro open redirect in @astrojs/node servermediumCVSS 4EPSS 0.5%
- CVE-2026-59729: withastro Astro XSS in renderHTMLElement spread attributesmediumCVSS 4EPSS 0.5%
- CVE-2026-59727: withastro Astro reflected XSS in transition directivesmediumCVSS 4EPSS 0.5%
- Astro CSRF protection bypass in astro/hono pipelinemediumCVSS 5.1
- Astro reflected XSS in View Transition animation propertiesmediumCVSS 5.3
- CVE-2026-59731: withastro Astro authorization bypass via URL decoding mismatchhighCVSS 8.2EPSS 0.5%
- CVE-2026-54299: withastro Astro SSRF in prerendered error page fetchhighCVSS 7.5EPSS 0.3%
- CVE-2026-54298: Astro XSS via unescaped attribute names in spread propertiesmediumCVSS 4.2EPSS 0.2%
- CVE-2026-50146: withastro Astro reflected XSS in data-astro-template attributehighCVSS 7.1EPSS 0.3%
- CVE-2026-30117: Scalar Astro XSS and Open Redirect in Scalar Proxy endpointinfoCVSS 6.1
- CVE-2026-45028: Astro cross-component replay in server islandsmediumCVSS 6.1EPSS 0.2%
- CVE-2026-41067: Astro: XSS in define:vars via incomplete </script> tag sanitizationmediumCVSS 6.1EPSS 0.3%
- CVE-2026-33769: Astro remotePatterns allowlist bypass via unanchored wildcardlowCVSS 3.1EPSS 0.4%
- CVE-2025-66202: Astro authentication bypass via double URL encodinglowCVSS 3.1EPSS 0.3%
- CVE-2025-65019: Astro Cloudflare adapter stored XSS in /_image endpointlowCVSS 3.1EPSS 0.3%
- CVE-2025-64765: Astro middleware authentication bypass via URL encodingmediumCVSS 4EPSS 0.5%
- CVE-2025-64764: Astro reflected XSS via server islands featurelowCVSS 3.1EPSS 0.5%
- CVE-2025-64757: Astro Development Server path traversal in image endpointlowCVSS 3.1EPSS 0.4%
- CVE-2025-64525: Astro URL manipulation via unsanitized headerslowCVSS 3.1EPSS 1.2%
- CVE-2025-64745: Astro development server reflected XSS in error pagelowCVSS 3.1EPSS 0.3%
Most severe astro (npm) vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- Astro remote code execution through AVIF image optimizationcriticalCVSS 9.8
- CVE-2026-59731: withastro Astro authorization bypass via URL decoding mismatchhighCVSS 8.2EPSS 0.5%
- CVE-2026-54299: withastro Astro SSRF in prerendered error page fetchhighCVSS 7.5EPSS 0.3%
- CVE-2026-50146: withastro Astro reflected XSS in data-astro-template attributehighCVSS 7.1EPSS 0.3%
- CVE-2026-41067: Astro: XSS in define:vars via incomplete </script> tag sanitizationmediumCVSS 6.1EPSS 0.3%
- CVE-2026-45028: Astro cross-component replay in server islandsmediumCVSS 6.1EPSS 0.2%
- Astro reflected XSS in View Transition animation propertiesmediumCVSS 5.3
- Astro CSRF protection bypass in astro/hono pipelinemediumCVSS 5.1
- CVE-2026-54298: Astro XSS via unescaped attribute names in spread propertiesmediumCVSS 4.2EPSS 0.2%
- CVE-2026-84376: Astro is a web framework for content-driven websites. Prior to 7.2.4, Astro stripped a configured non-root base path from…mediumCVSS 4EPSS 0.7%
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 29 Jun 2026 | 0 | 0 | |
| 6 Jul 2026 | 1 | 0 | |
| 13 Jul 2026 | 0 | 0 | |
| 20 Jul 2026 | 2 | 0 | |
| 27 Jul 2026 | 3 | 0 | |
| 3 Aug 2026 | 0 | 0 | |
| 10 Aug 2026 | 2 | 0 | |
| 17 Aug 2026 | 0 | 0 | |
| 24 Aug 2026 | 0 | 0 | |
| 31 Aug 2026 | 1 | 0 | |
| 7 Sep 2026 | 2 | 1 | |
| 14 Sep 2026 | 0 | 0 | |
| 21 Sep 2026 | 0 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/technologies/astro.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "astro (npm) vulnerabilities", https://junglewise.ai/threats/technologies/astro, 26 September 2026.