Vulnerabilities

ID
Packages
Summary
Published
arrow_upward
Attributes
GHSA-26w7-cxv4-gfx2
  • npm/astro
Astro: Remote code execution through AVIF image optimization 08 Sep
  • Fix available
  • Severity - 9.8 (Critical)
GHSA-376h-93r7-7g6f
  • npm/astro
Astro: Authorization bypass from missing path-segment boundary check when stripping the configured base 08 Sep
  • Fix available
  • Severity - 6.3 (Medium)
MAL-2026-13622
  • npm/@depup/astro
Malicious code in @depup/astro (npm) 07 Aug
  • No fix available
GHSA-8mv7-9c27-98vc
  • npm/astro
Astro: composable `astro/hono` pipeline bypasses `security.checkOrigin` when `middleware()` is absent or misordered 20 Jul
  • Fix available
  • Severity - 5.1 (Medium)
GHSA-f48w-9m4c-m7f5
  • npm/astro
Astro: XSS via unescaped spread attribute names in renderHTMLElement (incomplete fix for CVE-2026-54298) 20 Jul
  • Fix available
  • Severity - 5.1 (Medium)
GHSA-7pw4-f3q4-r2p2
  • npm/astro
Astro: Cross-site scripting via unescaped transition:* directive values on hydrated islands 20 Jul
  • Fix available
  • Severity - 2.1 (Low)
GHSA-vj59-8hwv-xxmv
  • npm/astro
Astro: Authorization Bypass via Decode Iteration Limit and Rewrite Path Canonicalization Mismatch 20 Jul
  • Fix available
  • Severity - 8.2 (High)
GHSA-4g3v-8h47-v7g6
  • npm/astro
Astro: Reflected XSS via unescaped View Transition animation properties 20 Jul
  • Fix available
  • Severity - 5.3 (Medium)
GHSA-jrpj-wcv7-9fh9
  • npm/astro
Astro: XSS via Unescaped Attribute Names in Spread Props 16 Jun
  • Fix available
  • Severity - 4.2 (Medium)
GHSA-2pvr-wf23-7pc7
  • npm/astro
Astro: Host header SSRF in prerendered error page fetch 16 Jun
  • Fix available
  • Severity - 7.5 (High)
GHSA-8hv8-536x-4wqp
  • npm/astro
Astro: Reflected XSS via unescaped slot name 16 Jun
  • Fix available
  • Severity - 7.1 (High)
GHSA-xr5h-phrj-8vxv
  • npm/astro
Astro: Server island encrypted parameters vulnerable to cross-component replay 13 May
  • Fix available
  • Severity - 2.9 (Low)
GHSA-w24r-5266-9c3c
  • npm/@clerk/astro
  • npm/@clerk/backend
  • npm/@clerk/chrome-extension
  • npm/@clerk/clerk-expo
  • npm/@clerk/clerk-js
  • ... 12 more
Clerk has an authorization bypass when combining organization, billing, or reverification checks 30 Apr
  • Fix available
  • Severity - 7.6 (High)
GHSA-j687-52p2-xcff
  • npm/astro
Astro: XSS in define:vars via incomplete </script> tag sanitization 21 Apr
  • Fix available
  • Severity - 6.1 (Medium)
GHSA-vqx2-fgx2-5wq9
  • npm/@clerk/astro
  • npm/@clerk/nextjs
  • npm/@clerk/nuxt
  • npm/@clerk/shared
Official Clerk JavaScript SDKs: Middleware-based route protection bypass 16 Apr
  • Fix available
  • Severity - 9.1 (Critical)
GHSA-g735-7g2w-hh3f
  • npm/astro
Astro: Remote allowlist bypass via unanchored matchPathname wildcard 26 Mar
  • Fix available
  • Severity - 2.9 (Low)