{"schema_version":1,"title":"astro (npm) vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 30 vulnerabilities in astro (npm): 0 in the last 7 days and 11 in the last 90 days, 1 of them critical and 0 exploited in the wild. The most recent, Astro remote code execution via AVIF image processing, was published on 8 September 2026.","url":"https://junglewise.ai/threats/technologies/astro","json_url":"https://junglewise.ai/threats/technologies/astro.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/technologies/astro","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"technology","counts":{"high":3,"all_time":30,"critical":1,"exploited":0,"last_7_days":0,"last_30_days":3,"last_90_days":11,"last_365_days":27},"latest":[{"cvss":3.1,"slug":"astro-remote-code-execution-via-avif-image-processing-6b99ffe8","title":"Astro remote code execution via AVIF image processing","severity":"low","exploited":false,"published_at":"2026-09-08T21:26:16+00:00","url":"https://junglewise.ai/threats/astro-remote-code-execution-via-avif-image-processing-6b99ffe8"},{"cvss":9.8,"slug":"astro-remote-code-execution-through-avif-image-optimization-79155f65","title":"Astro remote code execution through AVIF image optimization","severity":"critical","exploited":false,"published_at":"2026-09-08T21:26:16+00:00","url":"https://junglewise.ai/threats/astro-remote-code-execution-through-avif-image-optimization-79155f65"},{"cve":"CVE-2026-84376","cvss":4,"epss":0.0071,"slug":"cve-2026-84376-astro-authorization-bypass-in-base-path-stripping","title":"Astro is a web framework for content-driven websites. Prior to 7.2.4, Astro stripped a configured non-root base path from request pathnames","severity":"medium","exploited":false,"published_at":"2026-09-02T17:18:00.497+00:00","url":"https://junglewise.ai/threats/cve-2026-84376-astro-authorization-bypass-in-base-path-stripping"},{"cve":"CVE-2026-73423","cvss":4,"epss":0.0026,"slug":"cve-2026-73423-astro-composable-astro-hono-pipeline-csrf-via-origin-check-bypass","title":"Astro is a web framework for content-driven websites. From 7.0.0 until 7.0.6, the composable astro/hono pipeline installs security.checkOrig","severity":"medium","exploited":false,"published_at":"2026-08-12T21:17:41.34+00:00","url":"https://junglewise.ai/threats/cve-2026-73423-astro-composable-astro-hono-pipeline-csrf-via-origin-check-bypass"},{"cve":"CVE-2026-73422","cvss":4,"epss":0.0055,"slug":"cve-2026-73422-astro-reflected-xss-via-unescaped-view-transition-animation","title":"Astro is a web framework for content-driven websites. From 2.9.0 until 7.1.0, Astro's server-side View Transition CSS generator interpolates","severity":"medium","exploited":false,"published_at":"2026-08-12T21:17:41.187+00:00","url":"https://junglewise.ai/threats/cve-2026-73422-astro-reflected-xss-via-unescaped-view-transition-animation"},{"cve":"CVE-2026-59730","cvss":4,"epss":0.0046,"slug":"cve-2026-59730-withastro-astro-open-redirect-in-astrojs-node-server","title":"withastro Astro open redirect in @astrojs/node server","severity":"medium","exploited":false,"published_at":"2026-07-27T21:17:05.843+00:00","url":"https://junglewise.ai/threats/cve-2026-59730-withastro-astro-open-redirect-in-astrojs-node-server"},{"cve":"CVE-2026-59729","cvss":4,"epss":0.0054,"slug":"cve-2026-59729-withastro-astro-xss-in-renderhtmlelement-spread-attributes","title":"withastro Astro XSS in renderHTMLElement spread attributes","severity":"medium","exploited":false,"published_at":"2026-07-27T20:16:40.303+00:00","url":"https://junglewise.ai/threats/cve-2026-59729-withastro-astro-xss-in-renderhtmlelement-spread-attributes"},{"cve":"CVE-2026-59727","cvss":4,"epss":0.0054,"slug":"cve-2026-59727-withastro-astro-reflected-xss-in-transition-directives","title":"withastro Astro reflected XSS in transition directives","severity":"medium","exploited":false,"published_at":"2026-07-27T20:16:40.153+00:00","url":"https://junglewise.ai/threats/cve-2026-59727-withastro-astro-reflected-xss-in-transition-directives"},{"cvss":5.1,"slug":"astro-csrf-protection-bypass-in-astro-hono-pipeline-34b3f3bc","title":"Astro CSRF protection bypass in astro/hono pipeline","severity":"medium","exploited":false,"published_at":"2026-07-20T23:26:27+00:00","url":"https://junglewise.ai/threats/astro-csrf-protection-bypass-in-astro-hono-pipeline-34b3f3bc"},{"cvss":5.3,"slug":"astro-reflected-xss-in-view-transition-animation-properties-5ced3fe3","title":"Astro reflected XSS in View Transition animation properties","severity":"medium","exploited":false,"published_at":"2026-07-20T21:08:16+00:00","url":"https://junglewise.ai/threats/astro-reflected-xss-in-view-transition-animation-properties-5ced3fe3"},{"cve":"CVE-2026-59731","cvss":8.2,"epss":0.0047,"slug":"cve-2026-59731-withastro-astro-authorization-bypass-via-url-decoding-mismatch","title":"withastro Astro authorization bypass via URL decoding mismatch","severity":"high","exploited":false,"published_at":"2026-07-08T17:17:25.937+00:00","url":"https://junglewise.ai/threats/cve-2026-59731-withastro-astro-authorization-bypass-via-url-decoding-mismatch"},{"cve":"CVE-2026-54299","cvss":7.5,"epss":0.0033,"slug":"cve-2026-54299-withastro-astro-ssrf-in-prerendered-error-page-fetch","title":"withastro Astro SSRF in prerendered error page fetch","severity":"high","exploited":false,"published_at":"2026-06-22T19:17:21.26+00:00","url":"https://junglewise.ai/threats/cve-2026-54299-withastro-astro-ssrf-in-prerendered-error-page-fetch"},{"cve":"CVE-2026-54298","cvss":4.2,"epss":0.0023,"slug":"cve-2026-54298-astro-xss-via-unescaped-attribute-names-in-spread-properties","title":"Astro XSS via unescaped attribute names in spread properties","severity":"medium","exploited":false,"published_at":"2026-06-22T19:17:21.12+00:00","url":"https://junglewise.ai/threats/cve-2026-54298-astro-xss-via-unescaped-attribute-names-in-spread-properties"},{"cve":"CVE-2026-50146","cvss":7.1,"epss":0.0027,"slug":"cve-2026-50146-withastro-astro-reflected-xss-in-data-astro-template-attribute","title":"withastro Astro reflected XSS in data-astro-template attribute","severity":"high","exploited":false,"published_at":"2026-06-22T19:17:04.61+00:00","url":"https://junglewise.ai/threats/cve-2026-50146-withastro-astro-reflected-xss-in-data-astro-template-attribute"},{"cve":"CVE-2026-30117","cvss":6.1,"slug":"cve-2026-30117-scalar-astro-xss-and-open-redirect-in-scalar-proxy-endpoint","title":"Scalar Astro XSS and Open Redirect in Scalar Proxy endpoint","severity":"info","exploited":false,"published_at":"2026-05-19T16:16:19.98+00:00","url":"https://junglewise.ai/threats/cve-2026-30117-scalar-astro-xss-and-open-redirect-in-scalar-proxy-endpoint"},{"cve":"CVE-2026-45028","cvss":6.1,"epss":0.002,"slug":"cve-2026-45028-astro-server-island-cross-component-replay-vulnerability","title":"Astro cross-component replay in server islands","severity":"medium","exploited":false,"published_at":"2026-05-13T16:17:00.173+00:00","url":"https://junglewise.ai/threats/cve-2026-45028-astro-server-island-cross-component-replay-vulnerability"},{"cve":"CVE-2026-41067","cvss":6.1,"epss":0.0027,"slug":"cve-2026-41067-astro-xss-in-define-vars-via-incomplete-script-tag-sanitization","title":"Astro: XSS in define:vars via incomplete </script> tag sanitization","severity":"medium","exploited":false,"published_at":"2026-04-21T20:39:49+00:00","url":"https://junglewise.ai/threats/cve-2026-41067-astro-xss-in-define-vars-via-incomplete-script-tag-sanitization"},{"cve":"CVE-2026-33769","cvss":3.1,"epss":0.0036,"slug":"cve-2026-33769-astro-remotepatterns-allowlist-bypass-via-unanchored-wildcard","title":"Astro remotePatterns allowlist bypass via unanchored wildcard","severity":"low","exploited":false,"published_at":"2026-03-26T18:45:17+00:00","url":"https://junglewise.ai/threats/cve-2026-33769-astro-remotepatterns-allowlist-bypass-via-unanchored-wildcard"},{"cve":"CVE-2025-66202","cvss":3.1,"epss":0.0031,"slug":"cve-2025-66202-astro-authentication-bypass-via-double-url-encoding","title":"Astro authentication bypass via double URL encoding","severity":"low","exploited":false,"published_at":"2025-12-08T16:26:43+00:00","url":"https://junglewise.ai/threats/cve-2025-66202-astro-authentication-bypass-via-double-url-encoding"},{"cve":"CVE-2025-65019","cvss":3.1,"epss":0.0026,"slug":"cve-2025-65019-astro-cloudflare-adapter-stored-xss-in-image-endpoint","title":"Astro Cloudflare adapter stored XSS in /_image endpoint","severity":"low","exploited":false,"published_at":"2025-11-19T20:09:12+00:00","url":"https://junglewise.ai/threats/cve-2025-65019-astro-cloudflare-adapter-stored-xss-in-image-endpoint"},{"cve":"CVE-2025-64765","cvss":4,"epss":0.0051,"slug":"cve-2025-64765-astro-middleware-authentication-bypass-via-url-encoding","title":"Astro middleware authentication bypass via URL encoding","severity":"medium","exploited":false,"published_at":"2025-11-19T20:03:21+00:00","url":"https://junglewise.ai/threats/cve-2025-64765-astro-middleware-authentication-bypass-via-url-encoding"},{"cve":"CVE-2025-64764","cvss":3.1,"epss":0.0049,"slug":"cve-2025-64764-astro-reflected-xss-via-server-islands-feature","title":"Astro reflected XSS via server islands feature","severity":"low","exploited":false,"published_at":"2025-11-19T20:00:14+00:00","url":"https://junglewise.ai/threats/cve-2025-64764-astro-reflected-xss-via-server-islands-feature"},{"cve":"CVE-2025-64757","cvss":3.1,"epss":0.004,"slug":"cve-2025-64757-astro-development-server-path-traversal-in-image-endpoint","title":"Astro Development Server path traversal in image endpoint","severity":"low","exploited":false,"published_at":"2025-11-19T19:43:05+00:00","url":"https://junglewise.ai/threats/cve-2025-64757-astro-development-server-path-traversal-in-image-endpoint"},{"cve":"CVE-2025-64525","cvss":3.1,"epss":0.0116,"slug":"cve-2025-64525-astro-url-manipulation-via-unsanitized-headers","title":"Astro URL manipulation via unsanitized headers","severity":"low","exploited":false,"published_at":"2025-11-13T22:46:24+00:00","url":"https://junglewise.ai/threats/cve-2025-64525-astro-url-manipulation-via-unsanitized-headers"},{"cve":"CVE-2025-64745","cvss":3.1,"epss":0.0025,"slug":"cve-2025-64745-astro-development-server-reflected-xss-in-error-page","title":"Astro development server reflected XSS in error page","severity":"low","exploited":false,"published_at":"2025-11-13T22:38:30+00:00","url":"https://junglewise.ai/threats/cve-2025-64745-astro-development-server-reflected-xss-in-error-page"}],"weekly":[{"week":"2026-06-29","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":1},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":2},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":3},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":2},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":1},{"week":"2026-09-07","critical":1,"exploited":0,"vulnerabilities":2},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":0}],"related":[{"name":"flowise (npm)","slug":"flowise","vulnerabilities":156,"url":"https://junglewise.ai/threats/technologies/flowise"},{"name":"vm2 (npm)","slug":"vm2","vulnerabilities":82,"url":"https://junglewise.ai/threats/technologies/vm2"},{"name":"@budibase/server (npm)","slug":"budibase-server","vulnerabilities":61,"url":"https://junglewise.ai/threats/technologies/budibase-server"},{"name":"directus (npm)","slug":"directus","vulnerabilities":60,"url":"https://junglewise.ai/threats/technologies/directus"},{"name":"nocodb (npm)","slug":"nocodb","vulnerabilities":55,"url":"https://junglewise.ai/threats/technologies/nocodb"},{"name":"hono (npm)","slug":"hono","vulnerabilities":54,"url":"https://junglewise.ai/threats/technologies/hono"},{"name":"parse-server (npm)","slug":"parse-server","vulnerabilities":42,"url":"https://junglewise.ai/threats/technologies/parse-server"},{"name":"dompurify (npm)","slug":"dompurify","vulnerabilities":39,"url":"https://junglewise.ai/threats/technologies/dompurify"},{"name":"ghost (npm)","slug":"ghost","vulnerabilities":39,"url":"https://junglewise.ai/threats/technologies/ghost"},{"name":"flowise-components (npm)","slug":"flowise-components","vulnerabilities":35,"url":"https://junglewise.ai/threats/technologies/flowise-components"},{"name":"@anthropic-ai/claude-code (npm)","slug":"anthropic-ai-claude-code","vulnerabilities":28,"url":"https://junglewise.ai/threats/technologies/anthropic-ai-claude-code"},{"name":"9router (npm)","slug":"9router","vulnerabilities":26,"url":"https://junglewise.ai/threats/technologies/9router"}],"technology":{"hub":true,"name":"astro (npm)","slug":"astro","vendor":{"name":"npm","slug":"npm","url":"https://junglewise.ai/threats/vendors/npm"},"aliases":[],"homepage":"https://astro.build/","repo_url":"https://github.com/withastro/astro","description":"A web framework for building content-driven websites with a focus on performance and minimal client-side JavaScript.","url":"https://junglewise.ai/threats/technologies/astro"},"most_severe":[{"cvss":9.8,"slug":"astro-remote-code-execution-through-avif-image-optimization-79155f65","title":"Astro remote code execution through AVIF image optimization","severity":"critical","exploited":false,"published_at":"2026-09-08T21:26:16+00:00","url":"https://junglewise.ai/threats/astro-remote-code-execution-through-avif-image-optimization-79155f65"},{"cve":"CVE-2026-59731","cvss":8.2,"epss":0.0047,"slug":"cve-2026-59731-withastro-astro-authorization-bypass-via-url-decoding-mismatch","title":"withastro Astro authorization bypass via URL decoding mismatch","severity":"high","exploited":false,"published_at":"2026-07-08T17:17:25.937+00:00","url":"https://junglewise.ai/threats/cve-2026-59731-withastro-astro-authorization-bypass-via-url-decoding-mismatch"},{"cve":"CVE-2026-54299","cvss":7.5,"epss":0.0033,"slug":"cve-2026-54299-withastro-astro-ssrf-in-prerendered-error-page-fetch","title":"withastro Astro SSRF in prerendered error page fetch","severity":"high","exploited":false,"published_at":"2026-06-22T19:17:21.26+00:00","url":"https://junglewise.ai/threats/cve-2026-54299-withastro-astro-ssrf-in-prerendered-error-page-fetch"},{"cve":"CVE-2026-50146","cvss":7.1,"epss":0.0027,"slug":"cve-2026-50146-withastro-astro-reflected-xss-in-data-astro-template-attribute","title":"withastro Astro reflected XSS in data-astro-template attribute","severity":"high","exploited":false,"published_at":"2026-06-22T19:17:04.61+00:00","url":"https://junglewise.ai/threats/cve-2026-50146-withastro-astro-reflected-xss-in-data-astro-template-attribute"},{"cve":"CVE-2026-41067","cvss":6.1,"epss":0.0027,"slug":"cve-2026-41067-astro-xss-in-define-vars-via-incomplete-script-tag-sanitization","title":"Astro: XSS in define:vars via incomplete </script> tag sanitization","severity":"medium","exploited":false,"published_at":"2026-04-21T20:39:49+00:00","url":"https://junglewise.ai/threats/cve-2026-41067-astro-xss-in-define-vars-via-incomplete-script-tag-sanitization"},{"cve":"CVE-2026-45028","cvss":6.1,"epss":0.002,"slug":"cve-2026-45028-astro-server-island-cross-component-replay-vulnerability","title":"Astro cross-component replay in server islands","severity":"medium","exploited":false,"published_at":"2026-05-13T16:17:00.173+00:00","url":"https://junglewise.ai/threats/cve-2026-45028-astro-server-island-cross-component-replay-vulnerability"},{"cvss":5.3,"slug":"astro-reflected-xss-in-view-transition-animation-properties-5ced3fe3","title":"Astro reflected XSS in View Transition animation properties","severity":"medium","exploited":false,"published_at":"2026-07-20T21:08:16+00:00","url":"https://junglewise.ai/threats/astro-reflected-xss-in-view-transition-animation-properties-5ced3fe3"},{"cvss":5.1,"slug":"astro-csrf-protection-bypass-in-astro-hono-pipeline-34b3f3bc","title":"Astro CSRF protection bypass in astro/hono pipeline","severity":"medium","exploited":false,"published_at":"2026-07-20T23:26:27+00:00","url":"https://junglewise.ai/threats/astro-csrf-protection-bypass-in-astro-hono-pipeline-34b3f3bc"},{"cve":"CVE-2026-54298","cvss":4.2,"epss":0.0023,"slug":"cve-2026-54298-astro-xss-via-unescaped-attribute-names-in-spread-properties","title":"Astro XSS via unescaped attribute names in spread properties","severity":"medium","exploited":false,"published_at":"2026-06-22T19:17:21.12+00:00","url":"https://junglewise.ai/threats/cve-2026-54298-astro-xss-via-unescaped-attribute-names-in-spread-properties"},{"cve":"CVE-2026-84376","cvss":4,"epss":0.0071,"slug":"cve-2026-84376-astro-authorization-bypass-in-base-path-stripping","title":"Astro is a web framework for content-driven websites. Prior to 7.2.4, Astro stripped a configured non-root base path from request pathnames","severity":"medium","exploited":false,"published_at":"2026-09-02T17:18:00.497+00:00","url":"https://junglewise.ai/threats/cve-2026-84376-astro-authorization-bypass-in-base-path-stripping"}],"generated_at":"2026-09-26T10:14:00.201383+00:00"}