GHSA-376h-93r7-7g6f
Dashboard / Vulnerabilities / GHSA-376h-93r7-7g6f
Summary: Astro: Authorization bypass from missing path-segment boundary check when stripping the configured base
Details: ## Summary Astro stripped a configured `base` path from request pathnames using a string-prefix check that did not verify a path-segment boundary. With `base: "/app"`, a request to `/appX/admin` was treated as being under the base and resolved internally to the `/admin` route, while middleware still observed the public pathname `/appX/admin`. Middleware that authorizes routes by inspecting `context.url.pathname` could therefore be bypassed. ## Impact An unauthenticated remote attacker can bypass pathname-based middleware authorization in applications that: - Configure a non-root `base`. - Protect base-prefixed routes in middleware using `context.url.pathname`. Because routing and middleware resolved different effective pathnames, a request such as `/appX/admin` (or other single-character extensions like `/app2/admin` or `/app-/admin`) reached the protected `/admin` route without passing the middleware check that guards `/app/admin`. Astro's authentication guide demonstrates protecting routes in middleware via `context.url.pathname`, so this is a reasonable and expected pattern. ## Affected versions `astro` <= 7.2.3. ## Patches Fixed in `astro` 7.2.4. Base stripping now requires the pathname to equal the base without its trailing slash, or to be followed by a `/`, so a prefix that does not end on a path-segment boundary is no longer treated as being under the base. Routing and `context.url.pathname` now resolve the same pathname. ## Workarounds Upgrade to `astro` 7.2.4 or later. As a mitigation before upgrading, avoid relying solely on prefix checks of `context.url.pathname` for authorization, or reject requests whose pathname does not begin with the configured base followed by a path-segment boundary. ## Credits Reported by @Ryoga-exe.
References: https://github.com/withastro/astro/security/advisories/GHSA-376h-93r7-7g6f, https://nvd.nist.gov/vuln/detail/CVE-2026-84376, https://github.com/withastro/astro/pull/17701, https://github.com/withastro/astro/commit/05763a0884aabb1da78a2749d5bb9d41ae620527, https://github.com/withastro/astro, https://github.com/withastro/astro/releases/tag/[email protected]
Affected packages
Package
Name: astro
Purl: pkg:npm/astro
Affected ranges
Type: SEMVER
Events:
