Package compatibility

Astro

Node.js requirements from npm Registry (engines.node) for the astro package. This is not a lifecycle software page.

Compatibility is derived from the declared Node.js version requirement (npm engines.node). CompatHub does not independently test every combination.

Version lines

Each line reflects a declared engines.node tip. Requirement changes across tips appear as separate lines when present.

Known vulnerabilities

Recent OSV.dev advisories mapped to this product. CVSS/CWE from NVD and known-exploited status from CISA KEV when available. CompatHub is not the original vulnerability authority.

  • CVE-2026-73423GHSA-8mv7-9c27-98vc

    Astro: composable `astro/hono` pipeline bypasses `security.checkOrigin` when `middleware()` is absent or misordered

    Affected:
    >=7.0.0,<7.0.6
    Fixed in:
    7.0.6
    Source:
    OSV source
  • CVE-2026-59729GHSA-f48w-9m4c-m7f5

    Astro: XSS via unescaped spread attribute names in renderHTMLElement (incomplete fix for CVE-2026-54298)

    Affected:
    <7.0.6
    Fixed in:
    7.0.6
    Source:
    OSV source · Advisory
  • CVE-2026-59727GHSA-7pw4-f3q4-r2p2

    Astro: Cross-site scripting via unescaped transition:* directive values on hydrated islands

    Affected:
    >=3.10.0,<7.0.4
    Fixed in:
    7.0.4
    Source:
    OSV source · Advisory
  • CVE-2026-59731GHSA-vj59-8hwv-xxmv

    Astro: Authorization Bypass via Decode Iteration Limit and Rewrite Path Canonicalization Mismatch

    Affected:
    >=6.4.7,<6.4.8
    Fixed in:
    6.4.8
    Source:
    OSV source · Advisory
  • CVE-2026-73422GHSA-4g3v-8h47-v7g6

    Astro: Reflected XSS via unescaped View Transition animation properties

    Affected:
    >=2.9.0,<7.1.0
    Fixed in:
    7.1.0
    Source:
    OSV source
  • CVE-2026-54298GHSA-jrpj-wcv7-9fh9

    Astro: XSS via Unescaped Attribute Names in Spread Props

    Affected:
    <6.4.6
    Fixed in:
    6.4.6
    Source:
    OSV source · Advisory
  • CVE-2026-54299GHSA-2pvr-wf23-7pc7

    Astro: Host header SSRF in prerendered error page fetch

    Affected:
    <6.4.6
    Fixed in:
    6.4.6
    Source:
    OSV source · Advisory
  • CVE-2026-50146GHSA-8hv8-536x-4wqp

    Astro: Reflected XSS via unescaped slot name

    Affected:
    <6.3.3
    Fixed in:
    6.3.3
    Source:
    OSV source · Advisory
  • CVE-2026-45028GHSA-xr5h-phrj-8vxv

    Astro: Server island encrypted parameters vulnerable to cross-component replay

    Affected:
    <6.1.10
    Fixed in:
    6.1.10
    Source:
    OSV source · Advisory
  • CVE-2026-41067GHSA-j687-52p2-xcff

    Astro: XSS in define:vars via incomplete </script> tag sanitization

    Affected:
    <6.1.6
    Fixed in:
    6.1.6
    Source:
    OSV source · Advisory
  • CVE-2026-33769GHSA-g735-7g2w-hh3f

    Astro: Remote allowlist bypass via unanchored matchPathname wildcard

    Affected:
    >=2.10.10,<5.18.1
    Fixed in:
    5.18.1
    Source:
    OSV source · Advisory
  • CVE-2025-66202GHSA-whqg-ppgf-wp8c

    Astro has an Authentication Bypass via Double URL Encoding, a bypass for CVE-2025-64765

    Affected:
    <5.15.8
    Fixed in:
    5.15.8
    Source:
    OSV source · Advisory