CVE-2026-50146

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
22/06/2026
Last modified:
23/06/2026

Description

Astro is a web framework. Prior to 6.3.3, when a component uses a client:* directive, Astro inserts named slot content into a data-astro-template attribute without HTML escaping the slot name allowing an attacker to break out of the attribute context and inject arbitrary HTML, resulting in reflected XSS during SSR. This vulnerability is fixed in 6.3.3.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:astro:astro:*:*:*:*:*:node.js:*:* 6.3.3 (excluding)