XSS Vulnerability in Astro Web Framework Affecting Versions Prior to 7.0.6
CVE-2026-59729

5.1MEDIUM

Key Information:

Vendor

Withastro

Status
Vendor
CVE Published:
27 July 2026

What is CVE-2026-59729?

The Astro web framework is susceptible to Cross-Site Scripting (XSS) due to unescaped spread attribute names in the renderHTMLElement method. Versions before 7.0.6 allow untrusted property keys to be spread onto native-HTMLElement-subclass components, breaking out of the intended attribute context. This vulnerability arises because the rendering method does not properly sanitize these attributes, allowing for potential exploitation. The vulnerability was addressed in version 7.0.6, which includes necessary safeguards to prevent such issues.

Affected Version(s)

astro < 7.0.6

References

CVSS V4

Score:
5.1
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.