astro is vulnerable to Cross Site Scripting (XSS)
30
Low Risk
Affected versions of this package are vulnerable to cross-site scripting (XSS). The patched version strengthens the security of Server Islands slots by encrypting slot data before it is sent to the browser, aligning it with the security model already used for props. This ensures the integrity of slot content and prevents injection attacks, even when component templates do not explicitly support slots.
You are affected if you are using a version that falls within the vulnerable range.
astro is vulnerable to Cross Site Scripting (XSS) in versions 4.12.0 - 5.15.7.
Upgrade the astro library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant