VDB
Sign up
MEDIUM

GHSA-376h-93r7-7g6f

Astro: Authorization bypass from missing path-segment boundary check when stripping the configured base

Quick fix

GHSA-376h-93r7-7g6f — astro: upgrade to the fixed version with the command below.

npm install astro@7.2.4

Details

## Summary

Astro stripped a configured `base` path from request pathnames using a string-prefix check that did not verify a path-segment boundary. With `base: "/app"`, a request to `/appX/admin` was treated as being under the base and resolved internally to the `/admin` route, while middleware still observed the public pathname `/appX/admin`. Middleware that authorizes routes by inspecting `context.url.pathname` could therefore be bypassed.

## Impact

An unauthenticated remote attacker can bypass pathname-based middleware authorization in applications that:

- Configure a non-root `base`. - Protect base-prefixed routes in middleware using `context.url.pathname`.

Because routing and middleware resolved different effective pathnames, a request such as `/appX/admin` (or other single-character extensions like `/app2/admin` or `/app-/admin`) reached the protected `/admin` route without passing the middleware check that guards `/app/admin`. Astro's authentication guide demonstrates protecting routes in middleware via `context.url.pathname`, so this is a reasonable and expected pattern.

## Affected versions

`astro` <= 7.2.3.

## Patches

Fixed in `astro` 7.2.4. Base stripping now requires the pathname to equal the base without its trailing slash, or to be followed by a `/`, so a prefix that does not end on a path-segment boundary is no longer treated as being under the base. Routing and `context.url.pathname` now resolve the same pathname.

## Workarounds

Upgrade to `astro` 7.2.4 or later. As a mitigation before upgrading, avoid relying solely on prefix checks of `context.url.pathname` for authorization, or reject requests whose pathname does not begin with the configured base followed by a path-segment boundary.

## Credits

Reported by @Ryoga-exe.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/astro
Introduced in: 0Fixed in: 7.2.4
Fixnpm install astro@7.2.4

References