{"id":"GHSA-376h-93r7-7g6f","summary":"Astro: Authorization bypass from missing path-segment boundary check when stripping the configured base","details":"## Summary\n\nAstro stripped a configured `base` path from request pathnames using a string-prefix check that did not verify a path-segment boundary. With `base: \"/app\"`, a request to `/appX/admin` was treated as being under the base and resolved internally to the `/admin` route, while middleware still observed the public pathname `/appX/admin`. Middleware that authorizes routes by inspecting `context.url.pathname` could therefore be bypassed.\n\n## Impact\n\nAn unauthenticated remote attacker can bypass pathname-based middleware authorization in applications that:\n\n- Configure a non-root `base`.\n- Protect base-prefixed routes in middleware using `context.url.pathname`.\n\nBecause routing and middleware resolved different effective pathnames, a request such as `/appX/admin` (or other single-character extensions like `/app2/admin` or `/app-/admin`) reached the protected `/admin` route without passing the middleware check that guards `/app/admin`. Astro's authentication guide demonstrates protecting routes in middleware via `context.url.pathname`, so this is a reasonable and expected pattern.\n\n## Affected versions\n\n`astro` \u003c= 7.2.3.\n\n## Patches\n\nFixed in `astro` 7.2.4. Base stripping now requires the pathname to equal the base without its trailing slash, or to be followed by a `/`, so a prefix that does not end on a path-segment boundary is no longer treated as being under the base. Routing and `context.url.pathname` now resolve the same pathname.\n\n## Workarounds\n\nUpgrade to `astro` 7.2.4 or later. As a mitigation before upgrading, avoid relying solely on prefix checks of `context.url.pathname` for authorization, or reject requests whose pathname does not begin with the configured base followed by a path-segment boundary.\n\n## Credits\n\nReported by @Ryoga-exe.","aliases":["CVE-2026-84376"],"modified":"2026-09-08T21:30:04.767703624Z","published":"2026-09-08T21:26:02Z","database_specific":{"github_reviewed_at":"2026-09-08T21:26:02Z","nvd_published_at":"2026-09-02T17:18:00Z","cwe_ids":["CWE-187"],"severity":"MODERATE","github_reviewed":true},"references":[{"type":"WEB","url":"https://github.com/withastro/astro/security/advisories/GHSA-376h-93r7-7g6f"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-84376"},{"type":"WEB","url":"https://github.com/withastro/astro/pull/17701"},{"type":"WEB","url":"https://github.com/withastro/astro/commit/05763a0884aabb1da78a2749d5bb9d41ae620527"},{"type":"PACKAGE","url":"https://github.com/withastro/astro"},{"type":"WEB","url":"https://github.com/withastro/astro/releases/tag/astro@7.2.4"}],"affected":[{"package":{"name":"astro","ecosystem":"npm","purl":"pkg:npm/astro"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"7.2.4"}]}],"database_specific":{"last_known_affected_version_range":"\u003c= 7.2.3","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/09/GHSA-376h-93r7-7g6f/GHSA-376h-93r7-7g6f.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N"}]}