astro is vulnerable to Cross-Site Request Forgery (CSRF)
10
Low Risk
Affected versions of this package lack default protection against cross-site request forgery (CSRF). To mitigate this vulnerability, users of versions starting from 4.9.0 can explicitly enable protection by setting security.checkOrigin to true in the configuration, lower versions are not protected. The patched version addresses this issue by enabling CSRF protection by default. Updating to the latest version or adjusting the configuration is recommended to prevent unauthorized actions on behalf of authenticated users.
You are affected if you are using a version that falls within the vulnerable range.
astro is vulnerable to Cross-Site Request Forgery (CSRF) in versions 0.0.1 - 4.16.16.
Upgrade the astro library to the patch version or set security.checkOrigin to true if you have a version higher than 4.9.0.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant