What is CVE-2026-59729?
Astro web framework versions before 7.0.6 are vulnerable to XSS due to unescaped spread attribute names in the renderHTMLElement function. This could allow attackers to inject and execute arbitrary JavaScript in a user's browser. Users should immediately upgrade to version 7.0.6 or later.
Azərbaycanca: Astro veb freymvorkunun 7.0.6-dan əvvəlki versiyalarında renderHTMLElement funksiyasında spread atribut adlarının qaçışdırılmaması səbəbindən XSS zəifliyi mövcuddur. Bu, zərərli istifadəçiyə səhifədə ixtiyari JavaScript kodu icra etməyə imkan yarada bilər. Dərhal Astro-nu 7.0.6 və ya daha yuxarı versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-79
FAQ2
Which versions of the Astro web framework are vulnerable to the CVE-2026-59729 XSS vulnerability?
Astro versions before 7.0.6 are vulnerable to this weakness.
What should I do to fix the CVE-2026-59729 vulnerability?
You should immediately upgrade Astro to version 7.0.6 or later.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.