GHSA-26w7-cxv4-gfx2Critical· 9.8▾ MidnightAstro: Remote code execution through AVIF image optimization
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 53.9 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
A vulnerability in libheif, used by the default Sharp image service in Astro, can lead to remote code execution when a malicious AVIF image is optimized.
Projects are affected when an attacker can cause Astro to process an untrusted AVIF image.
The fix was released in Astro 7.2.8, which requires Sharp 0.35.4.
astro < 7.2.8Upgrade to a patched release:
astro 7.2.8Connected by shared product, vendor, weakness, or advisory.
CVE-2026-84376MediumAstro is a web framework for content-driven websites
CVE-2021-4034High· 7.8A local privilege escalation vulnerability was found on polkit's pkexec utility
CVE-2026-59727LowAstro: Cross-site scripting via unescaped transition:* directive values on hydrated islands
CVE-2026-59729MediumAstro: XSS via unescaped spread attribute names in renderHTMLElement (incomplete fix for CVE-2026-54298)
GHSA-8mv7-9c27-98vcMediumAstro: composable `astro/hono` pipeline bypasses `security.checkOrigin` when `middleware()` is absent or misordered
CVE-2026-59731High· 8.2Astro: Authorization Bypass via Decode Iteration Limit and Rewrite Path Canonicalization Mismatch