๐Ÿ” CVE Alert

CVE-2026-73424

MEDIUM 6.5

Astro: Unauthenticated path override in the @astrojs/vercel ISR function

CVSS Score
6.5
EPSS Score
0.0%
EPSS Percentile
0th

Astro is a web framework for content-driven websites. From 10.0.3 until 11.0.3, the Astro Vercel adapter in packages/integrations/vercel/src/serverless/entrypoint.ts accepts x_astro_path for the public /_isr function based only on the x-vercel-isr header, allowing unauthenticated GET requests to render routes protected only by Vercel edge path rules or split edge middleware. This issue is fixed in 11.0.3.

CWE CWE-441 CWE-862
Vendor withastro
Product astro
Published Aug 17, 2026
Stay Ahead of the Next One

Get instant alerts for withastro astro

Be the first to know when new medium vulnerabilities affecting withastro astro are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
Low
Integrity
Low
Availability
None

Affected Versions

withastro / astro
>= 10.0.3, < 11.0.3

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/withastro/astro/security/advisories/GHSA-x27w-589x-frm2 github.com: https://github.com/withastro/astro/pull/17370 github.com: https://github.com/withastro/astro/commit/3a43cf0f3690a8e33cb30109bc5165611cf38fcd github.com: https://github.com/withastro/astro/releases/tag/@astrojs/[email protected]