CVE-2026-59729
MEDIUM SEVERITYVulnerability Description
Astro: XSS via unescaped spread attribute names in renderHTMLElement (incomplete fix for CVE-2026-54298)
Vulnerability Details
Published Date
Last Modified
Source
GitHub
Vendor
npm
Product
astro
External References
- https://github.com/withastro/astro/security/advisories/GHSA-f48w-9m4c-m7f5
- https://github.com/withastro/astro/pull/17251
- https://github.com/withastro/astro/commit/5240e26c9dd91f9bc7140dcfacdb48d5a132830d
- https://github.com/withastro/astro/releases/tag/astro@7.0.6
- https://github.com/advisories/GHSA-f48w-9m4c-m7f5
Discussion (0)
Add Comment
No comments yet. Be the first!