Package compatibility

Astro 0.24

What Node.js versions does this Astro version support?

Compatibility is derived from the declared Node.js version requirement (npm engines.node). CompatHub does not independently test every combination.

Declared Node.js requirement

engines.node
^14.15.0 || >=16.0.0
Tip version
0.24.3
Source
npm Registry (engines.node)

Node.js compatibility matrix

Evaluated against CompatHub Node.js VersionLines. Compatibility and lifecycle status are separate signals.

Other Astro lines

Security

Advisories affecting Astro 0.24 (OSV.dev evidence). Known exploited status, due dates, and ransomware use from CISA KEV when matched.

Known vulnerabilities
15
Known exploited
0
Highest CVSS
  • CVE-2026-59729GHSA-f48w-9m4c-m7f5

    Astro: XSS via unescaped spread attribute names in renderHTMLElement (incomplete fix for CVE-2026-54298)

    Affected:
    <7.0.6
    Fixed in:
    7.0.6
    Source:
    OSV source · Advisory
  • CVE-2026-54298GHSA-jrpj-wcv7-9fh9

    Astro: XSS via Unescaped Attribute Names in Spread Props

    Affected:
    <6.4.6
    Fixed in:
    6.4.6
    Source:
    OSV source · Advisory
  • CVE-2026-54299GHSA-2pvr-wf23-7pc7

    Astro: Host header SSRF in prerendered error page fetch

    Affected:
    <6.4.6
    Fixed in:
    6.4.6
    Source:
    OSV source · Advisory
  • CVE-2026-50146GHSA-8hv8-536x-4wqp

    Astro: Reflected XSS via unescaped slot name

    Affected:
    <6.3.3
    Fixed in:
    6.3.3
    Source:
    OSV source · Advisory
  • CVE-2026-45028GHSA-xr5h-phrj-8vxv

    Astro: Server island encrypted parameters vulnerable to cross-component replay

    Affected:
    <6.1.10
    Fixed in:
    6.1.10
    Source:
    OSV source · Advisory
  • CVE-2026-41067GHSA-j687-52p2-xcff

    Astro: XSS in define:vars via incomplete </script> tag sanitization

    Affected:
    <6.1.6
    Fixed in:
    6.1.6
    Source:
    OSV source · Advisory
  • CVE-2025-66202GHSA-whqg-ppgf-wp8c

    Astro has an Authentication Bypass via Double URL Encoding, a bypass for CVE-2025-64765

    Affected:
    <5.15.8
    Fixed in:
    5.15.8
    Source:
    OSV source · Advisory
  • CVE-2025-65019GHSA-fvmw-cj7j-j39q

    Astro Cloudflare adapter has Stored Cross-site Scripting vulnerability in /_image endpoint

    Affected:
    <5.15.9
    Fixed in:
    5.15.9
    Source:
    OSV source · Advisory
  • CVE-2025-64765GHSA-ggxq-hp9w-j794

    Astro's middleware authentication checks based on url.pathname can be bypassed via url encoded values

    Affected:
    <5.15.8
    Fixed in:
    5.15.8
    Source:
    OSV source · Advisory
  • CVE-2025-64764GHSA-wrwg-2hg8-v723

    Astro vulnerable to reflected XSS via the server islands feature

    Affected:
    <5.15.8
    Fixed in:
    5.15.8
    Source:
    OSV source · Advisory
  • CVE-2025-64757GHSA-x3h8-62x9-952g

    Astro Development Server has Arbitrary Local File Read

    Affected:
    <5.14.3
    Fixed in:
    5.14.3
    Source:
    OSV source · Advisory
  • CVE-2025-61925GHSA-5ff5-9fcw-vg88

    Astro's `X-Forwarded-Host` is reflected without validation

    Affected:
    <5.14.3
    Fixed in:
    5.14.3
    Source:
    OSV source · Advisory
  • CVE-2025-55303GHSA-xf8x-j4p2-f749

    Astro allows unauthorized third-party images in _image endpoint

    Affected:
    <4.16.19
    Fixed in:
    4.16.19
    Source:
    OSV source · Advisory
  • CVE-2024-56159GHSA-49w6-73cw-chjr

    Astro's server source code is exposed to the public if sourcemaps are enabled

    Affected:
    <4.16.18
    Fixed in:
    4.16.18
    Source:
    OSV source · Advisory
  • CVE-2024-56140GHSA-c4pw-33h3-35xw

    Atro CSRF Middleware Bypass (security.checkOrigin)

    Affected:
    <4.16.17
    Fixed in:
    4.16.17
    Source:
    OSV source · Advisory