CVE-2026-59727

Astro is a web framework for content-driven websites. In versions 3.10.0 through 7.0.3, when a transition:persist, transition:scope, or transition:persist-props directive is applied to a client-hydrated (client:*) component, Astro copied the directive value onto the rendered <astro-island> element without HTML-escaping it. If a developer reflects attacker-controlled input into one of these directives, an attacker can break out of the attribute and inject arbitrary HTML/JavaScript into the server-rendered output, resulting in reflected cross-site scripting (XSS). Exploitation requires the application developer to have written a non-idiomatic pattern — passing untrusted, request-derived input directly into a transition directive. Astro applications that do not route untrusted input into these directives are unaffected. This issue has been fixed in version 7.0.4.
CVSS

No CVSS.

Configurations

No configuration.

History

28 Jul 2026, 16:19

Type Values Removed Values Added
References () https://github.com/withastro/astro/security/advisories/GHSA-7pw4-f3q4-r2p2 - () https://github.com/withastro/astro/security/advisories/GHSA-7pw4-f3q4-r2p2 -

27 Jul 2026, 20:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-07-27 20:16

Updated : 2026-07-28 16:19


NVD link : CVE-2026-59727

Mitre link : CVE-2026-59727

CVE.ORG link : CVE-2026-59727


JSON object : View

Products Affected

No product.

CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CWE-83

Improper Neutralization of Script in Attributes in a Web Page

CWE-116

Improper Encoding or Escaping of Output