๐Ÿ” CVE Alert

CVE-2026-59727

UNKNOWN 0.0

Astro: Cross-site scripting via unescaped transition:* directive values on hydrated islands

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Astro is a web framework for content-driven websites. In versions 3.10.0 through 7.0.3, when a transition:persist, transition:scope, or transition:persist-props directive is applied to a client-hydrated (client:*) component, Astro copied the directive value onto the rendered <astro-island> element without HTML-escaping it. If a developer reflects attacker-controlled input into one of these directives, an attacker can break out of the attribute and inject arbitrary HTML/JavaScript into the server-rendered output, resulting in reflected cross-site scripting (XSS). Exploitation requires the application developer to have written a non-idiomatic pattern โ€” passing untrusted, request-derived input directly into a transition directive. Astro applications that do not route untrusted input into these directives are unaffected. This issue has been fixed in version 7.0.4.

CWE CWE-79 CWE-83 CWE-116
Vendor withastro
Product astro
Published Jul 27, 2026
Stay Ahead of the Next One

Get instant alerts for withastro astro

Be the first to know when new unknown vulnerabilities affecting withastro astro are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

withastro / astro
>= 3.10.0, < 7.0.4

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/withastro/astro/security/advisories/GHSA-7pw4-f3q4-r2p2 github.com: https://github.com/withastro/astro/pull/17212 github.com: https://github.com/withastro/astro/commit/7ba0bb1dc7516e88caff9abd7767322af44b0294 github.com: https://github.com/withastro/astro/releases/tag/[email protected]