Remote Path Traversal Vulnerability in Astro Web Framework
CVE-2026-33769
2.9LOW
What is CVE-2026-33769?
The Astro web framework has a vulnerability in its remotePatterns path enforcement for remote URLs utilized by server-side fetchers, affecting versions from 2.10.10 up to but not including 5.18.1. The unanchored path matching logic for wildcard patterns allows attackers to exploit this flaw by fetching paths outside the intended allowlisted prefix on permissible hosts. This exposure can enable unauthorized access to sensitive data. A patch has been released in version 5.18.1 to address this issue.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
astro >= 2.10.10, < 5.18.1
