Security Advisory

CVE-2026-41067

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2026-04-24 16:57:22
Last updated 2026-04-24 18:16:55
Assigner GitHub_M
State PUBLISHED

Description

Astro is a web framework. Prior to 6.1.6, the defineScriptVars function in Astros server-side rendering pipeline uses a case-sensitive regex /</script>/g to sanitize values injected into inline <script> tags via the define:vars directive. HTML parsers close <script> elements case-insensitively and also accept whitespace or / before the closing >, allowing an attacker to bypass the sanitization with payloads like </Script>, </script >, or </script/> and inject arbitrary HTML/JavaScript. This vulnerability is fixed in 6.1.6.