Dependency scanning
Check whether astro is in your codebase
Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.
Malware Advisories
Vulnerabilities
GHSA-26w7-cxv4-gfx2
Astro: Remote code execution through AVIF image optimization
CVE-2026-84376
Astro: Authorization bypass from missing path-segment boundary check when stripping the configured base
CVE-2026-59727
Astro: Cross-site scripting via unescaped transition:* directive values on hydrated islands
CVE-2026-54299
Astro: Host header SSRF in prerendered error page fetch
CVE-2026-50146
Astro: Reflected XSS via unescaped slot name
CVE-2026-73422
Astro: Reflected XSS via unescaped View Transition animation properties
CVE-2026-59729
Astro: XSS via unescaped spread attribute names in renderHTMLElement (incomplete fix for CVE-2026-54298)
CVE-2026-73423
Astro: composable `astro/hono` pipeline bypasses `security.checkOrigin` when `middleware()` is absent or misordered
CVE-2026-59731
Astro: Authorization Bypass via Decode Iteration Limit and Rewrite Path Canonicalization Mismatch
CVE-2026-54298
Astro: XSS via Unescaped Attribute Names in Spread Props
CVE-2026-45028
Astro: Server island encrypted parameters vulnerable to cross-component replay
CVE-2026-41067
Astro: XSS in define:vars via incomplete </script> tag sanitization
CVE-2026-33769
Astro: Remote allowlist bypass via unanchored matchPathname wildcard
CVE-2025-64765
Astro's middleware authentication checks based on url.pathname can be bypassed via url encoded values
CVE-2025-66202
Astro has an Authentication Bypass via Double URL Encoding, a bypass for CVE-2025-64765
CVE-2025-54793
Astros's duplicate trailing slash feature leads to an open redirection security issue
CVE-2025-65019
Astro Cloudflare adapter has Stored Cross-site Scripting vulnerability in /_image endpoint
CVE-2025-55303
Astro allows unauthorized third-party images in _image endpoint
CVE-2025-64745
Astro development server error page is vulnerable to reflected Cross-site Scripting
CVE-2024-56159
Astro's server source code is exposed to the public if sourcemaps are enabled
CVE-2024-56140
Atro CSRF Middleware Bypass (security.checkOrigin)
CVE-2024-47885
DOM Clobbering Gadget found in astro's client-side router that leads to XSS
CVE-2025-64764
Astro vulnerable to reflected XSS via the server islands feature
CVE-2025-64757
Astro Development Server has Arbitrary Local File Read
CVE-2025-64525
Astro vulnerable to URL manipulation via headers, leading to middleware and CVE-2025-61925 bypass
CVE-2025-59837
Astro's bypass of image proxy domain validation leads to SSRF and potential XSS
CVE-2025-61925
Astro's `X-Forwarded-Host` is reflected without validation
Browse more npm advisories
Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →
Ready to move
Start Securing
Free, no credit card | First findings in minutes