GHSA-376h-93r7-7g6f
Astro: Authorization bypass from missing path-segment boundary check when stripping the configured base
Quick fix
GHSA-376h-93r7-7g6f — astro: upgrade to the fixed version with the command below.
npm install astro@7.2.4Details
## Summary
Astro stripped a configured `base` path from request pathnames using a string-prefix check that did not verify a path-segment boundary. With `base: "/app"`, a request to `/appX/admin` was treated as being under the base and resolved internally to the `/admin` route, while middleware still observed the public pathname `/appX/admin`. Middleware that authorizes routes by inspecting `context.url.pathname` could therefore be bypassed.
## Impact
An unauthenticated remote attacker can bypass pathname-based middleware authorization in applications that:
- Configure a non-root `base`. - Protect base-prefixed routes in middleware using `context.url.pathname`.
Because routing and middleware resolved different effective pathnames, a request such as `/appX/admin` (or other single-character extensions like `/app2/admin` or `/app-/admin`) reached the protected `/admin` route without passing the middleware check that guards `/app/admin`. Astro's authentication guide demonstrates protecting routes in middleware via `context.url.pathname`, so this is a reasonable and expected pattern.
## Affected versions
`astro` <= 7.2.3.
## Patches
Fixed in `astro` 7.2.4. Base stripping now requires the pathname to equal the base without its trailing slash, or to be followed by a `/`, so a prefix that does not end on a path-segment boundary is no longer treated as being under the base. Routing and `context.url.pathname` now resolve the same pathname.
## Workarounds
Upgrade to `astro` 7.2.4 or later. As a mitigation before upgrading, avoid relying solely on prefix checks of `context.url.pathname` for authorization, or reject requests whose pathname does not begin with the configured base followed by a path-segment boundary.
## Credits
Reported by @Ryoga-exe.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://github.com/withastro/astro/security/advisories/GHSA-376h-93r7-7g6f[WEB]
- https://nvd.nist.gov/vuln/detail/CVE-2026-84376[ADVISORY]
- https://github.com/withastro/astro/pull/17701[WEB]
- https://github.com/withastro/astro/commit/05763a0884aabb1da78a2749d5bb9d41ae620527[WEB]
- https://github.com/withastro/astro[PACKAGE]
- https://github.com/withastro/astro/releases/tag/astro@7.2.4[WEB]