Package compatibility
Astro 6.0.6
What Node.js versions does this Astro version support?
Compatibility is derived from the declared Node.js version requirement (npm engines.node). CompatHub does not independently test every combination.
Declared Node.js requirement
- engines.node
- >=22.12.0
- Tip version
- 6.4.8
- Source
- npm Registry (engines.node)
Node.js compatibility matrix
Evaluated against CompatHub Node.js VersionLines. Compatibility and lifecycle status are separate signals.
Other Astro lines
Security
Advisories affecting Astro 6.0.6 (OSV.dev evidence). Known exploited status, due dates, and ransomware use from CISA KEV when matched.
- Known vulnerabilities
- 6
- Known exploited
- 0
- Highest CVSS
- —
- CVE-2026-59729GHSA-f48w-9m4c-m7f5
Astro: XSS via unescaped spread attribute names in renderHTMLElement (incomplete fix for CVE-2026-54298)
- Affected:
- <7.0.6
- Fixed in:
- 7.0.6
- Source:
- OSV source · Advisory
- CVE-2026-54298GHSA-jrpj-wcv7-9fh9
Astro: XSS via Unescaped Attribute Names in Spread Props
- Affected:
- <6.4.6
- Fixed in:
- 6.4.6
- Source:
- OSV source · Advisory
- CVE-2026-54299GHSA-2pvr-wf23-7pc7
Astro: Host header SSRF in prerendered error page fetch
- Affected:
- <6.4.6
- Fixed in:
- 6.4.6
- Source:
- OSV source · Advisory
- CVE-2026-50146GHSA-8hv8-536x-4wqp
Astro: Reflected XSS via unescaped slot name
- Affected:
- <6.3.3
- Fixed in:
- 6.3.3
- Source:
- OSV source · Advisory
- CVE-2026-45028GHSA-xr5h-phrj-8vxv
Astro: Server island encrypted parameters vulnerable to cross-component replay
- Affected:
- <6.1.10
- Fixed in:
- 6.1.10
- Source:
- OSV source · Advisory
- CVE-2026-41067GHSA-j687-52p2-xcff
Astro: XSS in define:vars via incomplete </script> tag sanitization
- Affected:
- <6.1.6
- Fixed in:
- 6.1.6
- Source:
- OSV source · Advisory
