Remote Path Traversal Vulnerability in Astro Web Framework
CVE-2026-33769
2.9LOW
What is CVE-2026-33769?
The Astro web framework has a vulnerability in its remotePatterns path enforcement for remote URLs utilized by server-side fetchers, affecting versions from 2.10.10 up to but not including 5.18.1. The unanchored path matching logic for wildcard patterns allows attackers to exploit this flaw by fetching paths outside the intended allowlisted prefix on permissible hosts. This exposure can enable unauthorized access to sensitive data. A patch has been released in version 5.18.1 to address this issue.
Affected Version(s)
astro >= 2.10.10, < 5.18.1
