Skip to content

astro-5.18.2.tgz: 11 vulnerabilities (highest severity is: 8.2) #394

Description

@mend-for-github-com
Vulnerable Library - astro-5.18.2.tgz

Astro is a modern site builder with web best practices, performance, and DX front-of-mind.

Library home page: https://registry.npmjs.org/astro/-/astro-5.18.2.tgz

Sample Path to Dependency File: /tutorials/messages_api-node-rcs-rich_card/package.json

Path to vulnerable library: /tutorials/messages_api-node-rcs-rich_card/package.json,/tutorials/voice-javascript-build_call_menu/package.json,/tutorials/video-node-client-observability/package.json,/tutorials/video-javascript-client-observability/package.json,/sources/voice-javascript-build_call_menu/package.json,/sources/messages_api-node-rcs-branded_messaging/package.json,/sources/video-node-client-observability/package.json,/tutorials/messages_api-node-rcs-branded_messaging/package.json,/sources/voice-javascript-conversational_ai_bot/package.json,/sources/messages_api-node-rcs-rich_card/package.json,/tutorials/voice-javascript-conversational_ai_bot/package.json,/sources/video-javascript-client-observability/package.json

Found in HEAD commit: f400f39c07df86338418f7902a27a7c22c1442b4

Vulnerabilities

Vulnerability Severity CVSS Dependency Type Fixed in (astro version) Remediation Possible**
CVE-2026-73650 High 8.2 svgo-4.0.1.tgz Transitive N/A*
CVE-2026-73646 High 7.5 postcss-8.5.16.tgz Transitive N/A*
CVE-2026-54299 High 7.5 astro-5.18.2.tgz Direct https://github.com/withastro/astro.git - astro@6.4.6
CVE-2026-50146 High 7.1 astro-5.18.2.tgz Direct https://github.com/withastro/astro.git - 6.3.3
CVE-2026-73422 Medium 6.1 astro-5.18.2.tgz Direct https://github.com/withastro/astro.git - astro@7.1.0
CVE-2026-59729 Medium 6.1 astro-5.18.2.tgz Direct 7.0.5
CVE-2026-59727 Medium 6.1 astro-5.18.2.tgz Direct https://github.com/withastro/astro.git - astro@7.0.4
CVE-2026-67214 Medium 5.9 nanoid-3.3.15.tgz Transitive N/A*
CVE-2026-67213 Medium 5.9 detected in multiple dependencies Transitive N/A*
CVE-2026-69153 Medium 5.3 postcss-8.5.16.tgz Transitive N/A*
CVE-2026-54298 Medium 4.2 astro-5.18.2.tgz Direct https://github.com/withastro/astro.git - 6.4.6

*For some transitive vulnerabilities, there is no version of direct dependency with a fix. Check the "Details" section below to see if there is a version of transitive dependency where vulnerability is fixed.

**In some cases, Remediation PR cannot be created automatically for a vulnerability despite the availability of remediation

Details

CVE-2026-73650

Vulnerable Library - svgo-4.0.1.tgz

SVGO is a Node.js library and command-line application for optimizing vector images.

Library home page: https://registry.npmjs.org/svgo/-/svgo-4.0.1.tgz

Sample Path to Dependency File: /sources/voice_ai_flue-javascript-workshop/package.json

Path to vulnerable library: /sources/voice_ai_flue-javascript-workshop/package.json,/sources/video-javascript-signaling/package.json,/sources/video-javascript-one_to_one/package.json,/sources/voice-javascript-build_call_menu/package.json,/tutorials/vonage_video_android_app-feature-config/package.json,/sources/vonage_video_ios_app-feature-config/package.json,/tutorials/voice_ai_flue-javascript-workshop/package.json,/sources/vonage_video_react_app-feature-config/package.json,/tutorials/video-javascript-multiparty/package.json,/tutorials/vonage_video_ios_app-feature-config/package.json,/sources/vonage_video_react_app-feature-config4/package.json,/tutorials/voice-javascript-workshop/package.json,/tutorials/vonage_video_ios_app-theme-customization/package.json,/tutorials/vonage_video_react_app-local-setup/package.json,/tutorials/vonage_video_react_app-theme-customization/package.json,/sources/vonage_video_android_app-feature-config/package.json,/sources/webxr-javascript-workshop/package.json,/tutorials/voice-javascript-build_call_menu/package.json,/tutorials/video-javascript-one_to_one/package.json,/sources/vonage_video_react_app-local-setup/package.json,/tutorials/video-javascript-debugging/package.json,/tutorials/verify-android-silent_auth/package.json,/sources/video-javascript-archive_layouts/package.json,/tutorials/vonage_video_react_app-feature-config/package.json,/tutorials/vonage_video_android_app-theme-customization/package.json,/sources/vonage_video_ios_app-theme-customization/package.json,/sources/vonage_video_ios_app-feature-theme-config/package.json,/tutorials/video-javascript-signaling/package.json,/tutorials/package.json,/tutorials/video-javascript-multiparty_archiving/package.json,/tutorials/video-javascript-archive_layouts/package.json,/toolbar-app/package.json,/tutorials/verify-backend/package.json,/sources/video_learning_server-node-deploy/package.json,/tutorials/advanced-video-core-api-features/package.json,/tutorials/video_learning_server-node-deploy/package.json,/sources/video-javascript-multiparty/package.json,/sources/video-javascript-multiparty_archiving/package.json,/sources/voice-javascript-workshop/package.json,/sources/video-javascript-debugging/package.json,/tutorials/voice-node-app_to_app/package.json,/sources/verify-android-silent_auth/package.json,/sources/voice-javascript-conversational_ai_bot/package.json,/tutorials/webxr-javascript-workshop/package.json,/tutorials/voice-javascript-conversational_ai_bot/package.json,/sources/vonage_video_react_app-theme-customization/package.json,/sources/advanced-video-core-api-features/package.json,/sources/vonage_video_android_app-theme-customization/package.json

Dependency Hierarchy:

  • astro-5.18.2.tgz (Root Library)
    • svgo-4.0.1.tgz (Vulnerable Library)

Found in HEAD commit: f400f39c07df86338418f7902a27a7c22c1442b4

Found in base branch: main

Vulnerability Details

SVGO, short for SVG Optimizer, is a Node.js library and command-line application for optimizing SVG files. From version 1.0.0 until versions 2.8.3, 3.3.4, and 4.0.2, the removeScripts plugin, named removeScriptElement in versions 1 through 3, can leave executable content in optimized SVGs because it does not remove namespaced or prefixed script elements such as "svg:script" (svg:script) and, in versions 3 and 4, matches JavaScript URIs case sensitively. Applications that process untrusted SVG input with this plugin enabled and serve the result can allow scripts to execute when another user opens the SVG, exposing local storage or cookies. This issue is fixed in versions 2.8.3, 3.3.4, and 4.0.2.
Mend Note: The description of this vulnerability differs from MITRE.

Publish Date: 2026-08-13

URL: CVE-2026-73650

CVSS 3 Score Details (8.2)

Base Score Metrics:

  • Exploitability Metrics:
    • Attack Vector: Network
    • Attack Complexity: Low
    • Privileges Required: None
    • User Interaction: Required
    • Scope: Changed
  • Impact Metrics:
    • Confidentiality Impact: High
    • Integrity Impact: Low
    • Availability Impact: None

For more information on CVSS3 Scores, click here.

Suggested Fix

Type: Upgrade version

Release Date: 2026-08-13

Fix Resolution: https://github.com/svg/svgo.git - v4.0.2,https://github.com/svg/svgo.git - v3.3.4

CVE-2026-73646

Vulnerable Library - postcss-8.5.16.tgz

Tool for transforming styles with JS plugins

Library home page: https://registry.npmjs.org/postcss/-/postcss-8.5.16.tgz

Sample Path to Dependency File: /sources/voice-javascript-conversational_ai_bot/package.json

Path to vulnerable library: /sources/voice-javascript-conversational_ai_bot/package.json,/tutorials/voice-javascript-build_call_menu/package.json,/sources/voice-javascript-build_call_menu/package.json,/tutorials/voice-javascript-conversational_ai_bot/package.json

Dependency Hierarchy:

  • astro-5.18.2.tgz (Root Library)
    • vite-6.4.3.tgz
      • postcss-8.5.16.tgz (Vulnerable Library)

Found in HEAD commit: f400f39c07df86338418f7902a27a7c22c1442b4

Found in base branch: main

Vulnerability Details

PostCSS takes a CSS file and provides an API to analyze and modify its rules by transforming the rules into an Abstract Syntax Tree. Prior to 8.5.18, lib/previous-map.js loadMap() passes attacker-controlled sourceMappingURL values to join(dirname(opts.from), annotation), and loadFile() permits traversed or absolute .map paths, allowing untrusted CSS processed without map: false to disclose sourcesContent from arbitrary reachable .map files through result.map. This issue is fixed in version 8.5.18.

Publish Date: 2026-08-17

URL: CVE-2026-73646

CVSS 3 Score Details (7.5)

Base Score Metrics:

  • Exploitability Metrics:
    • Attack Vector: Network
    • Attack Complexity: Low
    • Privileges Required: None
    • User Interaction: None
    • Scope: Unchanged
  • Impact Metrics:
    • Confidentiality Impact: High
    • Integrity Impact: None
    • Availability Impact: None

For more information on CVSS3 Scores, click here.

Suggested Fix

Type: Upgrade version

Release Date: 2026-08-13

Fix Resolution: https://github.com/postcss/postcss.git - 8.5.18

CVE-2026-54299

Vulnerable Library - astro-5.18.2.tgz

Astro is a modern site builder with web best practices, performance, and DX front-of-mind.

Library home page: https://registry.npmjs.org/astro/-/astro-5.18.2.tgz

Sample Path to Dependency File: /tutorials/messages_api-node-rcs-rich_card/package.json

Path to vulnerable library: /tutorials/messages_api-node-rcs-rich_card/package.json,/tutorials/voice-javascript-build_call_menu/package.json,/tutorials/video-node-client-observability/package.json,/tutorials/video-javascript-client-observability/package.json,/sources/voice-javascript-build_call_menu/package.json,/sources/messages_api-node-rcs-branded_messaging/package.json,/sources/video-node-client-observability/package.json,/tutorials/messages_api-node-rcs-branded_messaging/package.json,/sources/voice-javascript-conversational_ai_bot/package.json,/sources/messages_api-node-rcs-rich_card/package.json,/tutorials/voice-javascript-conversational_ai_bot/package.json,/sources/video-javascript-client-observability/package.json

Dependency Hierarchy:

  • astro-5.18.2.tgz (Vulnerable Library)

Found in HEAD commit: f400f39c07df86338418f7902a27a7c22c1442b4

Found in base branch: main

Vulnerability Details

Astro is a web framework. Prior to 6.4.6, Astro SSR apps with prerendered error pages (/404 or /500 using export const prerender = true) fetch those pages over HTTP at runtime when an error occurs. The URL for this fetch is derived from request.url, which in turn gets its origin from the incoming Host header. When the Host header is not validated against allowedDomains, an attacker can point the fetch at an arbitrary host and read the response. This vulnerability is fixed in 6.4.6.

Publish Date: 2026-06-22

URL: CVE-2026-54299

CVSS 3 Score Details (7.5)

Base Score Metrics:

  • Exploitability Metrics:
    • Attack Vector: Network
    • Attack Complexity: High
    • Privileges Required: None
    • User Interaction: None
    • Scope: Changed
  • Impact Metrics:
    • Confidentiality Impact: High
    • Integrity Impact: Low
    • Availability Impact: None

For more information on CVSS3 Scores, click here.

Suggested Fix

Type: Upgrade version

Release Date: 2026-06-16

Fix Resolution: https://github.com/withastro/astro.git - astro@6.4.6

⛑️ Automatic Remediation will be attempted for this issue.

CVE-2026-50146

Vulnerable Library - astro-5.18.2.tgz

Astro is a modern site builder with web best practices, performance, and DX front-of-mind.

Library home page: https://registry.npmjs.org/astro/-/astro-5.18.2.tgz

Sample Path to Dependency File: /tutorials/messages_api-node-rcs-rich_card/package.json

Path to vulnerable library: /tutorials/messages_api-node-rcs-rich_card/package.json,/tutorials/voice-javascript-build_call_menu/package.json,/tutorials/video-node-client-observability/package.json,/tutorials/video-javascript-client-observability/package.json,/sources/voice-javascript-build_call_menu/package.json,/sources/messages_api-node-rcs-branded_messaging/package.json,/sources/video-node-client-observability/package.json,/tutorials/messages_api-node-rcs-branded_messaging/package.json,/sources/voice-javascript-conversational_ai_bot/package.json,/sources/messages_api-node-rcs-rich_card/package.json,/tutorials/voice-javascript-conversational_ai_bot/package.json,/sources/video-javascript-client-observability/package.json

Dependency Hierarchy:

  • astro-5.18.2.tgz (Vulnerable Library)

Found in HEAD commit: f400f39c07df86338418f7902a27a7c22c1442b4

Found in base branch: main

Vulnerability Details

Astro is a web framework. Prior to 6.3.3, when a component uses a client:* directive, Astro inserts named slot content into a data-astro-template attribute without HTML escaping the slot name allowing an attacker to break out of the attribute context and inject arbitrary HTML, resulting in reflected XSS during SSR. This vulnerability is fixed in 6.3.3.

Publish Date: 2026-06-22

URL: CVE-2026-50146

CVSS 3 Score Details (7.1)

Base Score Metrics:

  • Exploitability Metrics:
    • Attack Vector: Network
    • Attack Complexity: Low
    • Privileges Required: None
    • User Interaction: Required
    • Scope: Unchanged
  • Impact Metrics:
    • Confidentiality Impact: Low
    • Integrity Impact: High
    • Availability Impact: None

For more information on CVSS3 Scores, click here.

Suggested Fix

Type: Upgrade version

Release Date: 2026-06-16

Fix Resolution: https://github.com/withastro/astro.git - 6.3.3

⛑️ Automatic Remediation will be attempted for this issue.

CVE-2026-73422

Vulnerable Library - astro-5.18.2.tgz

Astro is a modern site builder with web best practices, performance, and DX front-of-mind.

Library home page: https://registry.npmjs.org/astro/-/astro-5.18.2.tgz

Sample Path to Dependency File: /tutorials/messages_api-node-rcs-rich_card/package.json

Path to vulnerable library: /tutorials/messages_api-node-rcs-rich_card/package.json,/tutorials/voice-javascript-build_call_menu/package.json,/tutorials/video-node-client-observability/package.json,/tutorials/video-javascript-client-observability/package.json,/sources/voice-javascript-build_call_menu/package.json,/sources/messages_api-node-rcs-branded_messaging/package.json,/sources/video-node-client-observability/package.json,/tutorials/messages_api-node-rcs-branded_messaging/package.json,/sources/voice-javascript-conversational_ai_bot/package.json,/sources/messages_api-node-rcs-rich_card/package.json,/tutorials/voice-javascript-conversational_ai_bot/package.json,/sources/video-javascript-client-observability/package.json

Dependency Hierarchy:

  • astro-5.18.2.tgz (Vulnerable Library)

Found in HEAD commit: f400f39c07df86338418f7902a27a7c22c1442b4

Found in base branch: main

Vulnerability Details

Astro is a web framework for content-driven websites. From 2.9.0 until 7.1.0, Astro's server-side View Transition CSS generator interpolates animation properties into an inline style element without escaping them for CSS and HTML contexts. An attacker-controlled View Transition animation value such as duration can terminate the generated style element and inject arbitrary HTML or JavaScript. The affected code is packages/astro/src/runtime/server/transition.ts; renderTransition passes sheet.toString() into markHTMLString(), while addAnimationProperty serializes duration through toTimeValue() and also handles easing, direction, delay, fillMode, and name. Exploitation requires an on-demand or server-rendered route to pass attacker-controlled data into a View Transition animation definition and can execute arbitrary JavaScript in the affected application's origin, allowing access to sensitive page data and authenticated actions available to the victim. This issue is fixed in version 7.1.0.

Publish Date: 2026-08-12

URL: CVE-2026-73422

CVSS 3 Score Details (6.1)

Base Score Metrics:

  • Exploitability Metrics:
    • Attack Vector: Network
    • Attack Complexity: Low
    • Privileges Required: None
    • User Interaction: Required
    • Scope: Changed
  • Impact Metrics:
    • Confidentiality Impact: Low
    • Integrity Impact: Low
    • Availability Impact: None

For more information on CVSS3 Scores, click here.

Suggested Fix

Type: Upgrade version

Release Date: 2026-08-12

Fix Resolution: https://github.com/withastro/astro.git - astro@7.1.0

⛑️ Automatic Remediation will be attempted for this issue.

CVE-2026-59729

Vulnerable Library - astro-5.18.2.tgz

Astro is a modern site builder with web best practices, performance, and DX front-of-mind.

Library home page: https://registry.npmjs.org/astro/-/astro-5.18.2.tgz

Sample Path to Dependency File: /tutorials/messages_api-node-rcs-rich_card/package.json

Path to vulnerable library: /tutorials/messages_api-node-rcs-rich_card/package.json,/tutorials/voice-javascript-build_call_menu/package.json,/tutorials/video-node-client-observability/package.json,/tutorials/video-javascript-client-observability/package.json,/sources/voice-javascript-build_call_menu/package.json,/sources/messages_api-node-rcs-branded_messaging/package.json,/sources/video-node-client-observability/package.json,/tutorials/messages_api-node-rcs-branded_messaging/package.json,/sources/voice-javascript-conversational_ai_bot/package.json,/sources/messages_api-node-rcs-rich_card/package.json,/tutorials/voice-javascript-conversational_ai_bot/package.json,/sources/video-javascript-client-observability/package.json

Dependency Hierarchy:

  • astro-5.18.2.tgz (Vulnerable Library)

Found in HEAD commit: f400f39c07df86338418f7902a27a7c22c1442b4

Found in base branch: main

Vulnerability Details

Astro is a web framework for content-driven websites. Versions prior to 7.0.6 are vulnerable to XSS through unescaped spread attribute names in renderHTMLElement. The fix for CVE-2026-54298 (GHSA-jrpj-wcv7-9fh9) added an INVALID_ATTR_NAME_CHAR guard to addAttribute() so that spread-prop attribute names containing "' >/= or whitespace are dropped. A second attribute-rendering path, renderHTMLElement() in packages/astro/src/runtime/server/render/dom.ts, has its own inline attribute loop that does not go through addAttribute() and was not updated. It interpolates the attribute name unescaped and only escapes the value, so untrusted prop keys spread onto a native-HTMLElement-subclass component can still break out of the attribute context. This issue has been fixed in version 7.0.6.

Publish Date: 2026-07-27

URL: CVE-2026-59729

CVSS 3 Score Details (6.1)

Base Score Metrics:

  • Exploitability Metrics:
    • Attack Vector: Network
    • Attack Complexity: Low
    • Privileges Required: None
    • User Interaction: Required
    • Scope: Changed
  • Impact Metrics:
    • Confidentiality Impact: Low
    • Integrity Impact: Low
    • Availability Impact: None

For more information on CVSS3 Scores, click here.

Suggested Fix

Type: Upgrade version

Release Date: 2026-07-21

Fix Resolution: 7.0.5

⛑️ Automatic Remediation will be attempted for this issue.

CVE-2026-59727

Vulnerable Library - astro-5.18.2.tgz

Astro is a modern site builder with web best practices, performance, and DX front-of-mind.

Library home page: https://registry.npmjs.org/astro/-/astro-5.18.2.tgz

Sample Path to Dependency File: /tutorials/messages_api-node-rcs-rich_card/package.json

Path to vulnerable library: /tutorials/messages_api-node-rcs-rich_card/package.json,/tutorials/voice-javascript-build_call_menu/package.json,/tutorials/video-node-client-observability/package.json,/tutorials/video-javascript-client-observability/package.json,/sources/voice-javascript-build_call_menu/package.json,/sources/messages_api-node-rcs-branded_messaging/package.json,/sources/video-node-client-observability/package.json,/tutorials/messages_api-node-rcs-branded_messaging/package.json,/sources/voice-javascript-conversational_ai_bot/package.json,/sources/messages_api-node-rcs-rich_card/package.json,/tutorials/voice-javascript-conversational_ai_bot/package.json,/sources/video-javascript-client-observability/package.json

Dependency Hierarchy:

  • astro-5.18.2.tgz (Vulnerable Library)

Found in HEAD commit: f400f39c07df86338418f7902a27a7c22c1442b4

Found in base branch: main

Vulnerability Details

Astro is a web framework for content-driven websites. In versions 3.10.0 through 7.0.3, when a transition:persist, transition:scope, or transition:persist-props directive is applied to a client-hydrated (client:*) component, Astro copied the directive value onto the rendered element without HTML-escaping it. If a developer reflects attacker-controlled input into one of these directives, an attacker can break out of the attribute and inject arbitrary HTML/JavaScript into the server-rendered output, resulting in reflected cross-site scripting (XSS). Exploitation requires the application developer to have written a non-idiomatic pattern — passing untrusted, request-derived input directly into a transition directive. Astro applications that do not route untrusted input into these directives are unaffected. This issue has been fixed in version 7.0.4.

Publish Date: 2026-07-27

URL: CVE-2026-59727

CVSS 3 Score Details (6.1)

Base Score Metrics:

  • Exploitability Metrics:
    • Attack Vector: Network
    • Attack Complexity: Low
    • Privileges Required: None
    • User Interaction: Required
    • Scope: Changed
  • Impact Metrics:
    • Confidentiality Impact: Low
    • Integrity Impact: Low
    • Availability Impact: None

For more information on CVSS3 Scores, click here.

Suggested Fix

Type: Upgrade version

Release Date: 2026-07-21

Fix Resolution: https://github.com/withastro/astro.git - astro@7.0.4

⛑️ Automatic Remediation will be attempted for this issue.

CVE-2026-67214

Vulnerable Library - nanoid-3.3.15.tgz

A tiny (116 bytes), secure URL-friendly unique string ID generator

Library home page: https://registry.npmjs.org/nanoid/-/nanoid-3.3.15.tgz

Sample Path to Dependency File: /sources/voice-javascript-build_call_menu/package.json

Path to vulnerable library: /sources/voice-javascript-build_call_menu/package.json,/sources/voice-javascript-conversational_ai_bot/package.json,/tutorials/voice-javascript-build_call_menu/package.json,/tutorials/voice-javascript-conversational_ai_bot/package.json

Dependency Hierarchy:

  • astro-5.18.2.tgz (Root Library)
    • vite-6.4.3.tgz
      • postcss-8.5.16.tgz
        • nanoid-3.3.15.tgz (Vulnerable Library)

Found in HEAD commit: f400f39c07df86338418f7902a27a7c22c1442b4

Found in base branch: main

Vulnerability Details

nanoid (Nano ID) before 3.3.16 and 5.1.16 contains an infinite loop in the customAlphabet and nanoid functions of its non-secure module (nanoid/non-secure). When these functions are given a negative size, the loop counter is decremented from a negative value and never reaches its termination condition, spinning indefinitely and hanging the calling thread. An application that passes an unvalidated, attacker-controlled negative size to these functions is exposed to a denial-of-service condition.

Publish Date: 2026-07-29

URL: CVE-2026-67214

CVSS 3 Score Details (5.9)

Base Score Metrics:

  • Exploitability Metrics:
    • Attack Vector: Network
    • Attack Complexity: High
    • Privileges Required: None
    • User Interaction: None
    • Scope: Unchanged
  • Impact Metrics:
    • Confidentiality Impact: None
    • Integrity Impact: None
    • Availability Impact: High

For more information on CVSS3 Scores, click here.

Suggested Fix

Type: Upgrade version

Release Date: 2026-07-29

Fix Resolution: https://github.com/ai/nanoid.git - 5.1.16

CVE-2026-67213

Vulnerable Libraries - nanoid-3.3.15.tgz, nanoid-3.3.16.tgz

nanoid-3.3.15.tgz

A tiny (116 bytes), secure URL-friendly unique string ID generator

Library home page: https://registry.npmjs.org/nanoid/-/nanoid-3.3.15.tgz

Sample Path to Dependency File: /sources/voice-javascript-build_call_menu/package.json

Path to vulnerable library: /sources/voice-javascript-build_call_menu/package.json,/sources/voice-javascript-conversational_ai_bot/package.json,/tutorials/voice-javascript-build_call_menu/package.json,/tutorials/voice-javascript-conversational_ai_bot/package.json

Dependency Hierarchy:

  • astro-5.18.2.tgz (Root Library)
    • vite-6.4.3.tgz
      • postcss-8.5.16.tgz
        • nanoid-3.3.15.tgz (Vulnerable Library)

nanoid-3.3.16.tgz

A tiny (116 bytes), secure URL-friendly unique string ID generator

Library home page: https://registry.npmjs.org/nanoid/-/nanoid-3.3.16.tgz

Sample Path to Dependency File: /tutorials/video-javascript-client-observability/package.json

Path to vulnerable library: /tutorials/video-javascript-client-observability/package.json,/tutorials/video-node-client-observability/package.json,/sources/messages_api-node-rcs-rich_card/package.json,/sources/messages_api-node-rcs-branded_messaging/package.json,/sources/video-javascript-client-observability/package.json,/tutorials/messages_api-node-rcs-branded_messaging/package.json,/sources/video-node-client-observability/package.json,/tutorials/messages_api-node-rcs-rich_card/package.json

Dependency Hierarchy:

  • astro-5.18.2.tgz (Root Library)
    • vite-6.4.3.tgz
      • postcss-8.5.23.tgz
        • nanoid-3.3.16.tgz (Vulnerable Library)

Found in HEAD commit: f400f39c07df86338418f7902a27a7c22c1442b4

Found in base branch: main

Vulnerability Details

nanoid (Nano ID) before 5.1.6 contains an infinite loop in the customAlphabet and customRandom functions. When these functions are configured with a size of 0, the internal generation loop never satisfies its exit condition and spins indefinitely, hanging the calling thread. An application that passes an unvalidated, attacker-controlled size of 0 to these functions is exposed to a denial-of-service condition.

Publish Date: 2026-07-29

URL: CVE-2026-67213

CVSS 3 Score Details (5.9)

Base Score Metrics:

  • Exploitability Metrics:
    • Attack Vector: Network
    • Attack Complexity: High
    • Privileges Required: None
    • User Interaction: None
    • Scope: Unchanged
  • Impact Metrics:
    • Confidentiality Impact: None
    • Integrity Impact: None
    • Availability Impact: High

For more information on CVSS3 Scores, click here.

Suggested Fix

Type: Upgrade version

Release Date: 2026-07-29

Fix Resolution: https://github.com/ai/nanoid.git - 5.1.6

CVE-2026-69153

Vulnerable Library - postcss-8.5.16.tgz

Tool for transforming styles with JS plugins

Library home page: https://registry.npmjs.org/postcss/-/postcss-8.5.16.tgz

Sample Path to Dependency File: /sources/voice-javascript-conversational_ai_bot/package.json

Path to vulnerable library: /sources/voice-javascript-conversational_ai_bot/package.json,/tutorials/voice-javascript-build_call_menu/package.json,/sources/voice-javascript-build_call_menu/package.json,/tutorials/voice-javascript-conversational_ai_bot/package.json

Dependency Hierarchy:

  • astro-5.18.2.tgz (Root Library)
    • vite-6.4.3.tgz
      • postcss-8.5.16.tgz (Vulnerable Library)

Found in HEAD commit: f400f39c07df86338418f7902a27a7c22c1442b4

Found in base branch: main

Vulnerability Details

PostCSS takes a CSS file and provides an API to analyze and modify its rules by transforming the rules into an Abstract Syntax Tree. Prior to 8.5.19, if from is unset, an attacker can cause PreviousMap.loadFile() to read an unintended source-map file by supplying an absolute or directory-traversal sourceMappingURL. The resulting map’s sources and sourcesContent may then be exposed to the application. This issue is fixed in version 8.5.19.

Publish Date: 2026-08-03

URL: CVE-2026-69153

CVSS 3 Score Details (5.3)

Base Score Metrics:

  • Exploitability Metrics:
    • Attack Vector: Network
    • Attack Complexity: Low
    • Privileges Required: None
    • User Interaction: None
    • Scope: Unchanged
  • Impact Metrics:
    • Confidentiality Impact: Low
    • Integrity Impact: None
    • Availability Impact: None

For more information on CVSS3 Scores, click here.

Suggested Fix

Type: Upgrade version

Release Date: 2026-08-03

Fix Resolution: https://github.com/postcss/postcss.git - 8.5.23

CVE-2026-54298

Vulnerable Library - astro-5.18.2.tgz

Astro is a modern site builder with web best practices, performance, and DX front-of-mind.

Library home page: https://registry.npmjs.org/astro/-/astro-5.18.2.tgz

Sample Path to Dependency File: /tutorials/messages_api-node-rcs-rich_card/package.json

Path to vulnerable library: /tutorials/messages_api-node-rcs-rich_card/package.json,/tutorials/voice-javascript-build_call_menu/package.json,/tutorials/video-node-client-observability/package.json,/tutorials/video-javascript-client-observability/package.json,/sources/voice-javascript-build_call_menu/package.json,/sources/messages_api-node-rcs-branded_messaging/package.json,/sources/video-node-client-observability/package.json,/tutorials/messages_api-node-rcs-branded_messaging/package.json,/sources/voice-javascript-conversational_ai_bot/package.json,/sources/messages_api-node-rcs-rich_card/package.json,/tutorials/voice-javascript-conversational_ai_bot/package.json,/sources/video-javascript-client-observability/package.json

Dependency Hierarchy:

  • astro-5.18.2.tgz (Vulnerable Library)

Found in HEAD commit: f400f39c07df86338418f7902a27a7c22c1442b4

Found in base branch: main

Vulnerability Details

Astro is a web framework. Prior to 6.4.6, the spreadAttributes function in Astro's server-side rendering pipeline iterates over object keys and passes them directly to addAttribute, which interpolates the key into the HTML output without escaping. When a developer uses the spread syntax {...props} on an HTML element and the object keys come from an untrusted source (API, CMS, URL parameters), an attacker can inject arbitrary HTML attributes including event handlers like onmousemove, onclick, or break out of the attribute context entirely to inject new elements. This vulnerability is fixed in 6.4.6.

Publish Date: 2026-06-22

URL: CVE-2026-54298

CVSS 3 Score Details (4.2)

Base Score Metrics:

  • Exploitability Metrics:
    • Attack Vector: Network
    • Attack Complexity: High
    • Privileges Required: None
    • User Interaction: Required
    • Scope: Unchanged
  • Impact Metrics:
    • Confidentiality Impact: Low
    • Integrity Impact: Low
    • Availability Impact: None

For more information on CVSS3 Scores, click here.

Suggested Fix

Type: Upgrade version

Origin: GHSA-jrpj-wcv7-9fh9

Release Date: 2026-06-16

Fix Resolution: https://github.com/withastro/astro.git - 6.4.6

⛑️ Automatic Remediation will be attempted for this issue.


⛑️Automatic Remediation will be attempted for this issue.

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions