astro vulnerabilities

Astro is a modern site builder with web best practices, performance, and DX front-of-mind.

  • latest version

    5.13.7

  • latest non vulnerable version

  • first published

    4 years ago

  • latest version published

    7 days ago

  • licenses detected

  • Direct Vulnerabilities

    Known vulnerabilities in the astro package. This does not include vulnerabilities belonging to this package’s dependencies.

    How to fix?

    Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.

    Fix for free
    VulnerabilityVulnerable Version
    • M
    Cross-site Scripting (XSS)

    <4.16.19>=5.0.0-alpha.0 <5.13.2
    • H
    Storage of File with Sensitive Data Under Web Root

    <4.16.18>=5.0.0-alpha.0 <5.0.8
    • M
    Cross-site Request Forgery (CSRF)

    <4.16.17
    • M
    Cross-site Scripting (XSS)

    >=3.0.0 <4.16.1
    • M
    Cross-site Scripting (XSS)

    <4.12.2

    Package versions

    1225 VERSIONS IN TOTAL See all versions
    versionpublisheddirect vulnerabilities
    5.13.79 Sep, 2025
    • 0
      C
    • 0
      H
    • 0
      M
    • 0
      L
    5.13.68 Sep, 2025
    • 0
      C
    • 0
      H
    • 0
      M
    • 0
      L
    5.13.529 Aug, 2025
    • 0
      C
    • 0
      H
    • 0
      M
    • 0
      L
    5.13.427 Aug, 2025
    • 0
      C
    • 0
      H
    • 0
      M
    • 0
      L
    5.13.322 Aug, 2025
    • 0
      C
    • 0
      H
    • 0
      M
    • 0
      L
    5.13.215 Aug, 2025
    • 0
      C
    • 0
      H
    • 0
      M
    • 0
      L
    5.13.115 Aug, 2025
    • 0
      C
    • 0
      H
    • 1
      M
    • 0
      L
    5.13.014 Aug, 2025
    • 0
      C
    • 0
      H
    • 1
      M
    • 0
      L
    5.12.98 Aug, 2025
    • 0
      C
    • 0
      H
    • 1
      M
    • 0
      L
    5.12.81 Aug, 2025
    • 0
      C
    • 0
      H
    • 1
      M
    • 0
      L