astro
Security Risk Profile
Security Risk Score
Comprehensive risk assessment based on 30 vulnerabilities, EPSS scores, exploitation status, and remediation availability.
📅 Data spans from October 14, 2024 to present
Threat Assessment
Severity Distribution
Exploit Likelihood
Age Distribution
Common Weaknesses (CWE)
Most Affected Products
Recent Vulnerabilities
See more →Astro: Unauthenticated path override in the @astrojs/vercel ISR function
Astro Booking Engine <= 1.4.0 - Cross-Site Request Forgery to Settings Reset
Astro 6.4.7 Authorization Bypass via Decode Iteration Limit and Rewrite Path Canonicalization Mismatch
Astro: XSS via Unescaped Attribute Names in Spread Props
Astro: Host-header full-read SSRF in core prerendered error-page fetch (prerenderedErrorPageFetch default + unvalidated createRequestFromNodeRequest URL)
Astro: Reflected XSS via unescaped slot name
Astro: Server island encrypted parameters vulnerable to cross-component replay
Astro: XSS via incomplete `</script>` sanitization in `define:vars` allows case-insensitive and whitespace-based bypass
Astro: Remote allowlist bypass via unanchored matchPathname wildcard
Astro: Unauthenticated Path Override via `x-astro-path` / `x_astro_path`
Monitor astro in Real-Time
Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.