vulns.co
/
GKData.io MCP

Astro · 1 min read

Astro: routing and authorization must agree on resource identity

Astro's base-path removal accepted a textual prefix without establishing a complete path segment. Routing and authorization middleware could consequently disagree about the requested resource. The maintainer bounds the authorization bypass to applications with a non-root base and pathname-based middleware protection; it is not a claim that every Astro application lacks authorization.

Open the reference Maintainer AdvisoryReviewed 2026-10-03

How to use this reference

The maintainer identifies 7.2.4 as patched, and its release notes confirm segment-aware base handling. Editorial lesson: a permission decision must bind to the same canonical resource that execution resolves. Review normalization contracts between middleware and routing, and preserve resource-level checks when public path representations change.

Before reading

  • URL path normalization and framework routing
  • Middleware authorization and canonical resource identity

Context and limits

  • CVE-2026-84376. matthewp published the advisory; Ryoga-exe is credited as reporter. The affected range is astro through 7.2.3.
  • The software release page displays August 19 without a year in retrieved text. A full patch-release date is therefore not asserted; it is distinct from advisory publication and resource-edition chronology.
  • No production compromise or individual bounty is established. Learning prerequisites and generalized review guidance are editorial.

Sources and provenance

  1. Authorization bypass from missing path-segment boundary check when stripping the configured base Astro · reviewed 2026-10-03
  2. astro@7.2.4 release Astro · reviewed 2026-10-03

Record reviewed 2026-10-03. Snapshot 53796974ace8. Open the complete JSON contract.

GitHub snapshot 2026-10-04

53796974ace8 · JSON exports & schemas · CC BY 4.0 content / MIT software