CVE-2026-50146General(astro / astro)

LOWCVSS 6.1 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Astro is a web framework. Prior to 6.3.3, when a component uses a client:* directive, Astro inserts named slot content into a data-astro-template attribute without HTML escaping the slot name allowing an attacker to break out of the attribute context and inject arbitrary HTML, resulting in reflected XSS during SSR. This vulnerability is fixed in 6.3.3.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-80

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • astro

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • Technical details provided in 1 signal
  • General: 1 classified signal
  • 1 total mentions across 1 day

Affected systems

Vendors
Products
astro

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-08-04: 1Technical Details · 2026-08-04: 108-04
Signal classification1 categories
General
1100.0%
Referenced assets8 URLs
Full discourse1 post
  • Marcin Dudek@MythThrazz
    General

    Here are the direct links to the most serious (High-severity) Astro CVEs: 1. CVE-2024-56159 (High) — Server source code exposure via sourcemaps NVD: https://nvd.nist.gov/vuln/detail/CVE-2024-56159 GitHub Advisory: https://github.com/withastro/astro/security/advisories/GHSA-49w6-73cw-chjr 2. CVE-2025-64764 (High, CVSS 7.1) — Reflected XSS via server islands http://CVE.org: https://www.cve.org/CVERecord?id=CVE-2025-64764 NVD: https://nvd.nist.gov/vuln/detail/CVE-2025-64764 GitHub Advisory: https://github.com/withastro/astro/security/advisories/GHSA-wrwg-2hg8-v723 3. CVE-2026-59731 (High, CVSS 8.2) — Authorization bypass (middleware path checks) Confirmed High in multiple trackers (Snyk, Hacktron, Release Alert) Related GitHub advisory: GHSA-vj59-8hwv-xxmv (searchable on the project’s security page) 4. CVE-2026-54299 (High, CVSS 7.5) — Host-header SSRF in prerendered error pages GitHub Advisory: https://github.com/withastro/astro/security/advisories/GHSA-2pvr-wf23-7pc7 5. CVE-2026-50146 (High, CVSS 7.1) — Reflected XSS via unescaped slot names Confirmed High in trackers and release notes Full official list of all Astro security advisories https://github.com/withastro/astro/security/advisories

    Post summary

    The text enumerates several high‑severity Astro CVEs with links to official advisories, providing brief technical descriptions but no PoC, exploit details, or patch information.

    0001057
    1.7K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appastroastro-node.js-

Explore more