{"id":"GHSA-r557-wffq-wvrc","summary":"@astrojs/node: Backslash-prefixed paths not recognized as internal by trailing-slash redirect","details":"### Impact\n\nWith `trailingSlash: 'always'` configured, the `@astrojs/node` standalone server's static file handler appends a trailing slash to request paths and issues a `301` redirect. Paths beginning with `/\\` (slash-backslash) were not recognized as internal paths, so the handler would echo the raw path back in the `Location` header. Because browsers treat `\\` as `/` per the WHATWG URL specification, the resulting redirect could resolve to an external host.\n\n**Preconditions:**\n- `trailingSlash: 'always'` must be set (non-default; the default is `'ignore'`)\n- The request path must not have a file extension in its final segment\n- An attacker must deliver the crafted link to a user\n\n### Patches\n\nFixed by treating backslash-prefixed paths the same as `//`-prefixed paths in `isInternalPath()`, so they are no longer rewritten with a trailing slash.\n\n### Workarounds\n\nUse the default `trailingSlash: 'ignore'` setting, which does not issue trailing-slash redirects in the static file handler.\n\n### References\n\n- [WHATWG URL spec: backslash normalization](https://url.spec.whatwg.org/#url-parsing)","aliases":["CVE-2026-59730"],"modified":"2026-08-12T20:45:07.791392853Z","published":"2026-07-20T23:22:22Z","database_specific":{"nvd_published_at":"2026-07-27T21:17:05Z","cwe_ids":["CWE-601"],"severity":"LOW","github_reviewed":true,"github_reviewed_at":"2026-07-20T23:22:22Z"},"references":[{"type":"WEB","url":"https://github.com/withastro/astro/security/advisories/GHSA-r557-wffq-wvrc"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-59730"},{"type":"WEB","url":"https://github.com/withastro/astro/pull/17252"},{"type":"WEB","url":"https://github.com/withastro/astro/commit/eb6f97e391ee587747e37609c255c7cd4b9cce3c"},{"type":"PACKAGE","url":"https://github.com/withastro/astro"},{"type":"WEB","url":"https://github.com/withastro/astro/releases/tag/@astrojs/node@11.0.2"}],"affected":[{"package":{"name":"@astrojs/node","ecosystem":"npm","purl":"pkg:npm/%40astrojs/node"},"ranges":[{"type":"SEMVER","events":[{"introduced":"8.1.0"},{"fixed":"11.0.2"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/07/GHSA-r557-wffq-wvrc/GHSA-r557-wffq-wvrc.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:N/SI:L/SA:N"}]}