MEDIUM🇬🇧 English

CVE-2026-54298

CVSS 4.2v3.1pub. 2026-06-22upd. 2026-06-23

Astro to framework webowy. Przed wersją 6.4.6 funkcja spreadAttributes w pipeline'u server-side renderingu Astro iteruje po kluczach obiektu i przekazuje je bezpośrednio do addAttribute, która interpoluje klucz do wyjścia HTML bez escapowania. Gdy deweloper użyje składni spread {...props} na elemencie HTML, a klucze obiektu pochodzą z niezaufanego źródła (API, CMS, parametry URL), atakujący może wstrzyknąć dowolne atrybuty HTML, w tym event handlery takie jak onmousemove czy onclick, lub całkowicie wyjść z kontekstu atrybutu, aby wstrzyknąć nowe elementy. Luka została naprawiona w wersji 6.4.6.

Pokaż oryginał (EN)

Astro is a web framework. Prior to 6.4.6, the spreadAttributes function in Astro's server-side rendering pipeline iterates over object keys and passes them directly to addAttribute, which interpolates the key into the HTML output without escaping. When a developer uses the spread syntax {...props} on an HTML element and the object keys come from an untrusted source (API, CMS, URL parameters), an attacker can inject arbitrary HTML attributes including event handlers like onmousemove, onclick, or break out of the attribute context entirely to inject new elements. This vulnerability is fixed in 6.4.6.

CVSS Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N
  • Astro

    APP
    Astro
    < 6.4.6
🔵
ZWERYFIKUJ U PRODUCENTA
Brak jednoznacznych danych o patchu. Sprawdź referencje od producenta.
Tagi
XSS
CWE
Referencje

Powiązane podatności

CVE-2026-50146HIGH7.1ten sam produkt

Astro is a web framework. Prior to 6.3.3, when a component uses a client:* directive, Astro inserts named slot...

CVE-2026-54299HIGH7.5ten sam produkt

Astro is a web framework. Prior to 6.4.6, Astro SSR apps with prerendered error pages (/404 or /500 using expo...

CVE-2025-64764HIGH7.1ten sam produkt

Astro is a web framework. Prior to version 5.15.8, a reflected XSS vulnerability is present when the server is...

CVE-2025-59837HIGH7.2ten sam produkt

Astro is a web framework that includes an image proxy. In versions 5.13.4 and later before 5.13.10, the image ...

CVE-2024-56159HIGH7.8ten sam produkt

Astro is a web framework for content-driven websites. A bug in the build process allows any unauthenticated us...