---
id: CVE-2026-59730
aliases:
  - GHSA-r557-wffq-wvrc
title: >-
  @astrojs/node: Backslash-prefixed paths not recognized as internal by
  trailing-slash redirect
summary: >-
  @astrojs/node: Backslash-prefixed paths not recognized as internal by
  trailing-slash redirect
severity: low
cwe:
  - CWE-601
vendor: astrojs
product: '@astrojs/node'
ecosystem: npm
affected:
  - '@astrojs/node >= 8.1.0, < 11.0.2'
patched:
  - '@astrojs/node 11.0.2'
published: '2026-07-20'
updated: '2026-07-20'
source: GHSA
sourceUrl: 'https://github.com/advisories/GHSA-r557-wffq-wvrc'
references:
  - url: 'https://github.com/withastro/astro/security/advisories/GHSA-r557-wffq-wvrc'
  - url: 'https://github.com/withastro/astro/pull/17252'
  - url: >-
      https://github.com/withastro/astro/commit/eb6f97e391ee587747e37609c255c7cd4b9cce3c
  - url: 'https://github.com/withastro/astro/releases/tag/@astrojs/node@11.0.2'
  - url: 'https://github.com/advisories/GHSA-r557-wffq-wvrc'
tags:
  - ghsa
  - npm
ingestedAt: '2026-07-20T23:44:02.313Z'
epss: 0.0046
epssPercentile: 0.37293
---

## Overview

### Impact

With `trailingSlash: 'always'` configured, the `@astrojs/node` standalone server's static file handler appends a trailing slash to request paths and issues a `301` redirect. Paths beginning with `/\` (slash-backslash) were not recognized as internal paths, so the handler would echo the raw path back in the `Location` header. Because browsers treat `\` as `/` per the WHATWG URL specification, the resulting redirect could resolve to an external host.

**Preconditions:**
- `trailingSlash: 'always'` must be set (non-default; the default is `'ignore'`)
- The request path must not have a file extension in its final segment
- An attacker must deliver the crafted link to a user

### Patches

Fixed by treating backslash-prefixed paths the same as `//`-prefixed paths in `isInternalPath()`, so they are no longer rewritten with a trailing slash.

### Workarounds

Use the default `trailingSlash: 'ignore'` setting, which does not issue trailing-slash redirects in the static file handler.

### References

- [WHATWG URL spec: backslash normalization](https://url.spec.whatwg.org/#url-parsing)

## Affected packages

- `@astrojs/node >= 8.1.0, < 11.0.2`

## Remediation

Upgrade to a patched release:

- `@astrojs/node 11.0.2`
