mediumVulnerability

CVE-2026-84376

## Summary Astro stripped a configured `base` path from request pathnames using a string-prefix check that did not verify a path-segment boundary. With `base: "/app"`, a request to `/appX/admin` was treated as being under the base and resolved internally to the `/admin` route, while middleware still observed the public pathname `/appX/admin`. Middleware that authorizes routes by inspecting `context.url.pathname` could therefore be bypassed. ## Impact An unauthenticated remote attacker can bypass pathname-based middleware authorization in applications that: - Configure a non-root `base`. - Protect base-prefixed routes in middleware using `context.url.pathname`. Because routing and middleware resolved different effective pathnames, a request such as `/appX/admin` (or other single-character extensions like `/app2/admin` or `/app-/admin`) reached the protected `/admin` route without passing the middleware check that guards `/app/admin`. Astro's authentication guide demonstrates protecting routes in middleware via `context.url.pathname`, so this is a reasonable and expected pattern. ## Affected versions `astro` <= 7.2.3. ## Patches Fixed in `astro` 7.2.4. Base stripping now requires the pathname to equal the base without its trailing slash, or to be followed by a `/`, so a prefix that does not end on a path-segment boundary is no longer treated as being under the base. Routing and `context.url.pathname` now resolve the same pathname. ## Workarounds Upgrade to `astro` 7.2.4 or later. As a mitigation before upgrading, avoid relying solely on prefix checks of `context.url.pathname` for authorization, or reject requests whose pathname does not begin with the configured base followed by a path-segment boundary. ## Credits Reported by @Ryoga-exe.

Properties

ghsa_id
GHSA-376h-93r7-7g6f
severity
medium
summary
Astro: Authorization bypass from missing path-segment boundary check when stripping the configured base
epss_score
0.00407
cve_id
CVE-2026-84376
is_ghsa_only
false
ghsa_published
2026-09-08T21:26:02Z
source_url
https://github.com/advisories/GHSA-376h-93r7-7g6f
epss_percentile
0.33976
ghsa_updated
2026-09-08T21:26:04Z

Related Entities (5)

ENRICHED_BY (1)

[Source]FIRST EPSS

AFFECTS (1)

[Software]npm/astro

HAS_WEAKNESS (1)

[Weakness]Partial String Comparison

REPORTED_BY (1)

[Source]GitHub Advisory Database

VULNERABLE_TO (1)

[Software]npm/astro

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-84376 — Ninja Signal Threat Intelligence | Ninja Signal