Vulnerability Description
Astro is a web framework. Prior to 6.1.6, the defineScriptVars function in Astro's server-side rendering pipeline uses a case-sensitive regex /<\/script>/g to sanitize values injected into inline <script> tags via the define:vars directive. HTML parsers close <script> elements case-insensitively and also accept whitespace or / before the closing >, allowing an attacker to bypass the sanitization with payloads like </Script>, </script >, or </script/> and inject arbitrary HTML/JavaScript. This vulnerability is fixed in 6.1.6.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Astro | Astro | < 6.1.6 |
Related Weaknesses (CWE)
References
- https://github.com/withastro/astro/security/advisories/GHSA-j687-52p2-xcffExploitMitigationVendor Advisory
- https://github.com/withastro/astro/security/advisories/GHSA-j687-52p2-xcffExploitMitigationVendor Advisory
FAQ
What is CVE-2026-41067?
CVE-2026-41067 is a vulnerability with a CVSS score of 6.1 (MEDIUM). Astro is a web framework. Prior to 6.1.6, the defineScriptVars function in Astro's server-side rendering pipeline uses a case-sensitive regex /<\/script>/g to sanitize values injected into inline <scr...
How severe is CVE-2026-41067?
CVE-2026-41067 has been rated MEDIUM with a CVSS base score of 6.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-41067?
Check the references section above for vendor advisories and patch information. Affected products include: Astro Astro.