CVE-2026-54298
Last modified
CVE-2026-54298 is a medium-severity vulnerability rated 6.1/10 on the CVSS scale. Astro is a web framework. Prior to 6.4.6, the spreadAttributes function in Astro's server-side rendering pipeline iterates over object keys and passes them directly to addAttribute, which interpolates the key into the HTML output without escaping. EPSS estimates a 0.16% chance of exploitation in the next 30 days.
Description
Astro is a web framework. Prior to 6.4.6, the spreadAttributes function in Astro's server-side rendering pipeline iterates over object keys and passes them directly to addAttribute, which interpolates the key into the HTML output without escaping. When a developer uses the spread syntax {...props} on an HTML element and the object keys come from an untrusted source (API, CMS, URL parameters), an attacker can inject arbitrary HTML attributes including event handlers like onmousemove, onclick, or break out of the attribute context entirely to inject new elements. This vulnerability is fixed in 6.4.6.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Astro | Astro | < 6.4.6 |
References
- https://github.com/withastro/astro/security/advisories/GHSA-jrpj-wcv7-9fh9Exploit, Vendor Advisory
- https://github.com/withastro/astro/security/advisories/GHSA-jrpj-wcv7-9fh9Exploit, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2026-54298?
How severe is CVE-2026-54298?
How do I fix CVE-2026-54298?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-54292Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMB…
- CVE-2026-54293NLTK (Natural Language Toolkit) is a suite of open source Py…7.5
- CVE-2026-54294Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMB…
- CVE-2026-54295Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMB…
- CVE-2026-54296Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMB…
- CVE-2026-54297Faraday is an HTTP client library abstraction layer that pro…7.5
- CVE-2026-54299Astro is a web framework. Prior to 6.4.6, Astro SSR apps wit…7.5
- CVE-2026-5430The JWT authentication mechanism accepts tokens signed with …10
- CVE-2026-54300@astrojs/netlify is an adapter that allows Astro to deploy y…5.3
- CVE-2026-54301n8n is an open source workflow automation platform. Prior to…5.4
- CVE-2026-54302n8n is an open source workflow automation platform. Prior to…5.4
- CVE-2026-54303n8n is an open source workflow automation platform. Prior to…5.4
Are you affected by CVE-2026-54298?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
