What is CVE-2026-59727?
In Astro web framework versions 3.10.0 through 7.0.3, applying `transition:persist`, `transition:scope`, or `transition:persist-props` directives to `client:*` components copies the directive values to the rendered `astro-island` element, potentially causing data leakage. Affected users should update the framework or limit the use of these directives as a workaround.
Azərbaycanca: Astro veb framework-unun 3.10.0-7.0.3 versiyalarında `transition` direktivləri (`transition:persist`, `transition:scope`, `transition:persist-props`) `client:*` komponentlərində istifadə edildikdə, direktiv dəyərləri `astro-island` elementinə kopyalanır və bu, məlumat sızmasına səbəb ola bilər. Təsirə məruz qalan istifadəçilər framework-u yeniləməli və ya müvəqqəti olaraq bu direktivlərin istifadəsini məhdudlaşdırmalıdır.
FAQ2
Which versions of the Astro framework are affected by CVE-2026-59727?
Astro versions 3.10.0 through 7.0.3 are affected by this vulnerability.
Which directives cause data leakage in CVE-2026-59727?
The `transition:persist`, `transition:scope`, and `transition:persist-props` directives, when used on `client:*` components, copy their values to the `astro-island` element, which can lead to data leakage.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.