28 Total advisories
27 Vulnerabilities
1 Malware

Dependency scanning

Check whether astro is in your codebase

Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.

Vulnerabilities

CRITICAL 9.8
npm

GHSA-26w7-cxv4-gfx2

Astro: Remote code execution through AVIF image optimization

UNKNOWN
npm

CVE-2026-84376

Astro: Authorization bypass from missing path-segment boundary check when stripping the configured base

UNKNOWN
npm

CVE-2026-59727

Astro: Cross-site scripting via unescaped transition:* directive values on hydrated islands

HIGH 7.5
npm

CVE-2026-54299

Astro: Host header SSRF in prerendered error page fetch

HIGH 7.1
npm

CVE-2026-50146

Astro: Reflected XSS via unescaped slot name

UNKNOWN
npm

CVE-2026-73422

Astro: Reflected XSS via unescaped View Transition animation properties

UNKNOWN
npm

CVE-2026-59729

Astro: XSS via unescaped spread attribute names in renderHTMLElement (incomplete fix for CVE-2026-54298)

UNKNOWN
npm

CVE-2026-73423

Astro: composable `astro/hono` pipeline bypasses `security.checkOrigin` when `middleware()` is absent or misordered

HIGH 8.2
npm

CVE-2026-59731

Astro: Authorization Bypass via Decode Iteration Limit and Rewrite Path Canonicalization Mismatch

MEDIUM 4.2
npm

CVE-2026-54298

Astro: XSS via Unescaped Attribute Names in Spread Props

MEDIUM 6.1
npm

CVE-2026-45028

Astro: Server island encrypted parameters vulnerable to cross-component replay

MEDIUM 6.1
npm

CVE-2026-41067

Astro: XSS in define:vars via incomplete </script> tag sanitization

MEDIUM 5.3
npm

CVE-2026-33769

Astro: Remote allowlist bypass via unanchored matchPathname wildcard

UNKNOWN
npm

CVE-2025-64765

Astro's middleware authentication checks based on url.pathname can be bypassed via url encoded values

MEDIUM 6.5
npm

CVE-2025-66202

Astro has an Authentication Bypass via Double URL Encoding, a bypass for CVE-2025-64765

UNKNOWN
npm

CVE-2025-54793

Astros's duplicate trailing slash feature leads to an open redirection security issue

MEDIUM 5.4
npm

CVE-2025-65019

Astro Cloudflare adapter has Stored Cross-site Scripting vulnerability in /_image endpoint

MEDIUM 6.1
npm

CVE-2025-55303

Astro allows unauthorized third-party images in _image endpoint

LOW 2.7
npm

CVE-2025-64745

Astro development server error page is vulnerable to reflected Cross-site Scripting

UNKNOWN
npm

CVE-2024-56159

Astro's server source code is exposed to the public if sourcemaps are enabled

MEDIUM 5.9
npm

CVE-2024-56140

Atro CSRF Middleware Bypass (security.checkOrigin)

MEDIUM 5.9
npm

CVE-2024-47885

DOM Clobbering Gadget found in astro's client-side router that leads to XSS

HIGH 7.1
npm

CVE-2025-64764

Astro vulnerable to reflected XSS via the server islands feature

LOW 3.5
npm

CVE-2025-64757

Astro Development Server has Arbitrary Local File Read

MEDIUM 6.5
npm

CVE-2025-64525

Astro vulnerable to URL manipulation via headers, leading to middleware and CVE-2025-61925 bypass

HIGH 7.2
npm

CVE-2025-59837

Astro's bypass of image proxy domain validation leads to SSRF and potential XSS

MEDIUM 6.5
npm

CVE-2025-61925

Astro's `X-Forwarded-Host` is reflected without validation

Learn What is SAST?

Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →

Ready to move

Start Securing

Free, no credit card | First findings in minutes