PT-2026-49731 · Astro · Astro
CVSS v3.1
7.1
High
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Astro versions prior to 6.3.3
Description
When a component utilizes a
client:* directive, the software inserts named slot content into a data-astro-template attribute without performing HTML escaping on the slot name. This allows an attacker to break out of the attribute context and inject arbitrary HTML, leading to reflected Cross-Site Scripting (XSS) during Server-Side Rendering (SSR), which is the process of rendering web pages on the server instead of the browser.Recommendations
Update to version 6.3.3.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Astro