Astro is a web framework for content-driven websites. In versions 3.10.0 through 7.0.3, when a transition:persist, transition:scope, or transition:persist-props directive is applied to a client-hydrated (client:*) component, Astro copied the directive value onto the rendered <astro-island> element without HTML-escaping it. If a developer reflects attacker-controlled input into one of these directives, an attacker can break out of the attribute and inject arbitrary HTML/JavaScript into the server-rendered output, resulting in reflected cross-site scripting (XSS). Exploitation requires the application developer to have written a non-idiomatic pattern — passing untrusted, request-derived input directly into a transition directive. Astro applications that do not route untrusted input into these directives are unaffected. This issue has been fixed in version 7.0.4.
CVSS
No CVSS.
References
Configurations
No configuration.
History
28 Jul 2026, 16:19
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://github.com/withastro/astro/security/advisories/GHSA-7pw4-f3q4-r2p2 - |
27 Jul 2026, 20:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-07-27 20:16
Updated : 2026-07-28 16:19
NVD link : CVE-2026-59727
Mitre link : CVE-2026-59727
CVE.ORG link : CVE-2026-59727
JSON object : View
Products Affected
No product.
