astro is vulnerable to Authentication Bypass Using an Alternate Path or Channel
80
High Risk
Affected versions of this package are vulnerable to authentication bypass through double-URL encoded paths. An attacker could use multi-level URL encoding (e.g. /%2561dmin) to access routes that should be behind authentication. The patch fixes this by decoding pathnames and rejecting requests that contain leftover percent-encoded sequences after decoding.
You are affected if you are using a version that falls within the vulnerable range.
astro is vulnerable to Authentication Bypass Using an Alternate Path or Channel in versions 3.5.6 - 5.16.2.
Upgrade the astro library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant