Astro是Astro团队开源的一个内容驱动网站的 web 框架。 Astro 6.3.3之前版本存在跨站脚本漏洞,该漏洞源于当组件使用client:*指令时,Astro将命名槽内容插入data-astro-template属性且未对槽名称进行HTML转义,可能允许攻击者突破属性环境并注入任意HTML,导致服务端渲染期间的反射型跨站脚本攻击。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
| CVE-2026-54299 | 7.5 HIGH | Astro: Host-header full-read SSRF in core prerendered error-page fetch (prerenderedErrorPa |
| CVE-2026-54300 | 5.3 MEDIUM | @astrojs/netlify broadens Astro image.remotePatterns in Netlify Image CDN config |
| CVE-2026-54298 | 4.2 MEDIUM | Astro: XSS via Unescaped Attribute Names in Spread Props |
No comments yet