{"id":"CVE-2026-73423","summary":"Astro: composable `astro/hono` pipeline bypasses `security.checkOrigin` when `middleware()` is absent or misordered","details":"Astro is a web framework for content-driven websites. From 7.0.0 until 7.0.6, the composable astro/hono pipeline installs security.checkOrigin only through the middleware() primitive, while actions() and pages() can dispatch to user code independently. Mounting actions() before middleware(), as in the examples/advanced-routing example and Cloudflare Hono documentation, allows cross-origin form-encoded action requests to execute before the origin check, and using pages() without middleware() drops the check for on-demand endpoints and pages. The flaw enables blind write-only cross-site request forgery using the victim's cookies against ActionHandler.handle and PagesHandler.handleWithErrorFallback when manifest.checkOrigin is enabled; the attacker can trigger a state-mutating action or endpoint handler but cannot read the cross-origin response. The default non-composable astro() pipeline is not affected. This issue is fixed in version 7.0.6.","aliases":["GHSA-8mv7-9c27-98vc"],"modified":"2026-08-15T11:31:25.150763373Z","published":"2026-08-12T20:35:32.181Z","database_specific":{"cna_assigner":"GitHub_M","cwe_ids":["CWE-352"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/73xxx/CVE-2026-73423.json"},"references":[{"type":"WEB","url":"https://github.com/withastro/astro/releases/tag/astro@7.0.6"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/73xxx/CVE-2026-73423.json"},{"type":"ADVISORY","url":"https://github.com/withastro/astro/security/advisories/GHSA-8mv7-9c27-98vc"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-73423"},{"type":"FIX","url":"https://github.com/withastro/astro/commit/0b30b35f864310bee8485c952d1877e82e2b9b1a"},{"type":"FIX","url":"https://github.com/withastro/astro/pull/17250"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/withastro/astro","events":[{"introduced":"f55ba4caca7c587555da86e3211ae1f1b3407c5f"},{"fixed":"0b30b35f864310bee8485c952d1877e82e2b9b1a"},{"fixed":"a86160ee79e4600bf77f89eb2dc84782acdeab6f"}],"database_specific":{"extracted_events":[{"introduced":"7.0.0"},{"fixed":"7.0.6"}],"source":["AFFECTED_FIELD","REFERENCES"]}}],"versions":["astro@7.0.5","astro-vscode@2.16.17","@astrojs/vue@7.0.1","@astrojs/vercel@11.0.1","@astrojs/svelte@9.0.1","@astrojs/node@11.0.1","@astrojs/netlify@8.1.0","@astrojs/mdx@7.0.1","@astrojs/markdoc@2.0.2","@astrojs/cloudflare@14.1.0","create-astro@5.2.1","astro@7.0.4","@astrojs/rss@4.0.19","@astrojs/cloudflare@14.0.2","create-astro@5.2.0","astro@7.0.3","@astrojs/upgrade@0.7.3","@astrojs/markdoc@2.0.1","@astrojs/cloudflare@14.0.1","astro@7.0.2","@astrojs/markdown-satteri@0.3.2","astro@7.0.1","create-astro@5.1.0","astro@7.0.0","@astrojs/vue@7.0.0","@astrojs/vercel@11.0.0","@astrojs/svelte@9.0.0","@astrojs/solid-js@7.0.0","@astrojs/react@6.0.0","@astrojs/preact@6.0.0","@astrojs/node@11.0.0","@astrojs/netlify@8.0.0","@astrojs/mdx@7.0.0","@astrojs/markdown-satteri@0.3.1","@astrojs/markdoc@2.0.0","@astrojs/cloudflare@14.0.0","@astrojs/alpinejs@1.0.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-73423.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:N/SI:L/SA:N"}]}