Astro: Authorization bypass from missing path-segment boundary check when stripping the configured base
GHSA-376h-93r7-7g6f · CVE-2026-84376
Published · Modified
AI SAST
Find this class of vulnerability in your own code
Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.
Description
Summary
Astro stripped a configured base path from request pathnames using a string-prefix check that did not verify a path-segment boundary. With base: "/app", a request to /appX/admin was treated as being under the base and resolved internally to the /admin route, while middleware still observed the public pathname /appX/admin. Middleware that authorizes routes by inspecting context.url.pathname could therefore be bypassed.
Impact
An unauthenticated remote attacker can bypass pathname-based middleware authorization in applications that:
- Configure a non-root
base. - Protect base-prefixed routes in middleware using
context.url.pathname.
Because routing and middleware resolved different effective pathnames, a request such as /appX/admin (or other single-character extensions like /app2/admin or /app-/admin) reached the protected /admin route without passing the middleware check that guards /app/admin. Astro's authentication guide demonstrates protecting routes in middleware via context.url.pathname, so this is a reasonable and expected pattern.
Affected versions
astro <= 7.2.3.
Patches
Fixed in astro 7.2.4. Base stripping now requires the pathname to equal the base without its trailing slash, or to be followed by a /, so a prefix that does not end on a path-segment boundary is no longer treated as being under the base. Routing and context.url.pathname now resolve the same pathname.
Workarounds
Upgrade to astro 7.2.4 or later. As a mitigation before upgrading, avoid relying solely on prefix checks of context.url.pathname for authorization, or reject requests whose pathname does not begin with the configured base followed by a path-segment boundary.
Credits
Reported by @Ryoga-exe.
References
- WEB https://github.com/withastro/astro/security/advisories/GHSA-376h-93r7-7g6f
- ADVISORY https://nvd.nist.gov/vuln/detail/CVE-2026-84376
- WEB https://github.com/withastro/astro/pull/17701
- WEB https://github.com/withastro/astro/commit/05763a0884aabb1da78a2749d5bb9d41ae620527
- PACKAGE https://github.com/withastro/astro
- WEB https://github.com/withastro/astro/releases/tag/astro@7.2.4
Ready to move
Start Securing
Free, no credit card | First findings in minutes