2.9 LOW
- CVSS version (CVSS): 4.0
- Attack Vector (AV): Network (N)
- Attack Complexity (AC): Low (L)
- Attack Requirement (AT): Present (P)
- Privileges Required (PR): None (N)
- User Interaction (UI): None (N)
- Vulnerable System Impact Confidentiality (VC): None (N)
- Vulnerable System Impact Integrity (VI): Low (L)
- Vulnerable System Impact Availability (VA): None (N)
- Subsequent System Impact Confidentiality (SC): None (N)
- Subsequent System Impact Integrity (SI): None (N)
- Subsequent System Impact Availability (SA): None (N)
- Exploit Maturity (E): POC (P)
- Modified Attack Vector (MAV): Network (N)
- Modified Attack Complexity (MAC): Low (L)
- Modified Attack Requirement (MAT): Present (P)
- Modified Privileges Required (MPR): None (N)
- Modified User Interaction (MUI): None (N)
- Modified Vulnerable System Impact Confidentiality (MVC): None (N)
- Modified Vulnerable System Impact Integrity (MVI): Low (L)
- Modified Vulnerable System Impact Availability (MVA): None (N)
- Modified Subsequent System Impact Confidentiality (MSC): Negligible (N)
- Modified Subsequent System Impact Integrity (MSI): Negligible (N)
- Modified Subsequent System Impact Availability (MSA): Negligible (N)
- Safety (S): Not Defined (X)
- Automatable (AU): Not Defined (X)
- Recovery (R): Not Defined (X)
- Value Density (V): Not Defined (X)
- Vulnerability Response Effort (RE): Not Defined (X)
- Provider Urgency (U): Not Defined (X)
- Confidentiality Req. (CR): Not Defined (X)
- Integrity Req. (IR): Not Defined (X)
- Availability Req. (AR): Not Defined (X)
Activity log
- Created suggestion
Astro: Server island encrypted parameters vulnerable to cross-component replay
Astro is a web framework. Astro versions prior to 6.1.10 used AES-GCM encryption to protect the confidentiality and integrity of server island props and slots parameters, but did not bind the ciphertext to its intended component or parameter type. An attacker could replay one component's encrypted props (p) value as another component's slots (s) value, or vice versa. Since slots contain raw unescaped HTML while props may contain user-controlled values, this could lead to XSS in applications. This occurs when the application uses server islands, two different server island components share the same key name for a prop and a slot, and an attacker has full control over the value of the overlapping prop (requires a dynamically rendered page). This vulnerability is fixed in 6.1.10.
References
-
https://github.com/withastro/astro/security/advisories/GHSA-xr5h-phrj-8vxv x_refsource_CONFIRM
-
https://github.com/withastro/astro/pull/16457 x_refsource_MISC
Affected products
- ==< 6.1.10
Matching in nixpkgs
pkgs.astroid
GTK frontend to the notmuch mail system
pkgs.astrolog
Freeware astrology program
pkgs.gnuastro
GNU astronomy utilities and library
pkgs.astroterm
Celestial viewer for the terminal, written in C
pkgs.astronomer
Tool to detect illegitimate stars from bot accounts on GitHub projects
pkgs.astromenace
Hardcore 3D space shooter with spaceship upgrade possibilities
pkgs.sddm-astronaut
Modern looking qt6 sddm theme
-
nixos-unstable 0-unstable-2025-12-06
- nixpkgs-unstable 0-unstable-2025-12-06
- nixos-unstable-small 0-unstable-2025-12-06
-
nixos-25.11 1.0-unstable-2025-01-05
- nixos-25.11-small 1.0-unstable-2025-01-05
- nixpkgs-25.11-darwin 1.0-unstable-2025-01-05
pkgs.astrolabe-generator
Java-based tool for generating EPS files for constructing astrolabes and related tools
pkgs.typstPackages.astro
Draw beautiful astronomical diagrams
pkgs.astro-language-server
Astro language server
pkgs.python312Packages.astroid
Abstract syntax tree for Python with inference support
pkgs.python312Packages.astropy
Astronomy/Astrophysics library for Python
pkgs.python313Packages.astroid
Abstract syntax tree for Python with inference support
pkgs.python313Packages.astropy
Astronomy/Astrophysics library for Python
pkgs.python314Packages.astroid
Abstract syntax tree for Python with inference support
pkgs.python314Packages.astropy
Astronomy/Astrophysics library for Python
pkgs.typstPackages.astro_0_1_0
Draw beautiful astronomical diagrams
pkgs.indi-3rdparty.indi-astroasis
Third party drivers for the INDI astronomical software suite
-
nixos-unstable 3rdparty-indi-astroasis-2.2.0
- nixpkgs-unstable 3rdparty-indi-astroasis-2.2.0
- nixos-unstable-small 3rdparty-indi-astroasis-2.2.0
-
nixos-25.11 3rdparty-indi-astroasis-2.1.6.2
- nixos-25.11-small 3rdparty-indi-astroasis-2.1.6.2
- nixpkgs-25.11-darwin 3rdparty-indi-astroasis-2.1.6.2
pkgs.perlPackages.AstroFITSHeader
Object-oriented interface to FITS HDUs
pkgs.python312Packages.astroquery
Functions and classes to access online data resources
pkgs.python313Packages.astroquery
Functions and classes to access online data resources
pkgs.python314Packages.astroquery
Functions and classes to access online data resources
pkgs.perl5Packages.AstroFITSHeader
Object-oriented interface to FITS HDUs
pkgs.python312Packages.asdf-astropy
Extension library for ASDF to provide support for Astropy
pkgs.python313Packages.asdf-astropy
Extension library for ASDF to provide support for Astropy
pkgs.python314Packages.asdf-astropy
Extension library for ASDF to provide support for Astropy
pkgs.azure-cli-extensions.astronomer
Microsoft Azure Command-Line Tools Astronomer Extension
pkgs.perl538Packages.AstroFITSHeader
Object-oriented interface to FITS HDUs
pkgs.perl540Packages.AstroFITSHeader
Object-oriented interface to FITS HDUs
pkgs.python312Packages.pytest-astropy
Meta-package containing dependencies for testing
pkgs.python313Packages.pytest-astropy
Meta-package containing dependencies for testing
pkgs.python314Packages.pytest-astropy
Meta-package containing dependencies for testing
pkgs.python312Packages.astropy-healpix
BSD-licensed HEALPix for Astropy
pkgs.python312Packages.astropy-helpers
Utilities for building and installing Astropy, Astropy affiliated packages, and their respective documentation
pkgs.python313Packages.astropy-healpix
BSD-licensed HEALPix for Astropy
pkgs.python313Packages.astropy-helpers
Utilities for building and installing Astropy, Astropy affiliated packages, and their respective documentation
pkgs.python314Packages.astropy-healpix
BSD-licensed HEALPix for Astropy
pkgs.python314Packages.astropy-helpers
Utilities for building and installing Astropy, Astropy affiliated packages, and their respective documentation
pkgs.python312Packages.astropy-iers-data
IERS data maintained by @astrofrog and astropy.utils.iers maintainers
-
nixos-25.11 0.2026.1.19.0.42.31
- nixos-25.11-small 0.2026.1.19.0.42.31
- nixpkgs-25.11-darwin 0.2026.1.19.0.42.31
pkgs.python313Packages.astropy-iers-data
IERS data maintained by @astrofrog and astropy.utils.iers maintainers
-
nixos-unstable 0.2026.1.19.0.42.31
- nixpkgs-unstable 0.2026.1.19.0.42.31
- nixos-unstable-small 0.2026.1.19.0.42.31
-
nixos-25.11 0.2026.1.19.0.42.31
- nixos-25.11-small 0.2026.1.19.0.42.31
- nixpkgs-25.11-darwin 0.2026.1.19.0.42.31
pkgs.python314Packages.astropy-iers-data
IERS data maintained by @astrofrog and astropy.utils.iers maintainers
-
nixos-unstable 0.2026.1.19.0.42.31
- nixpkgs-unstable 0.2026.1.19.0.42.31
- nixos-unstable-small 0.2026.1.19.0.42.31
pkgs.tree-sitter-grammars.tree-sitter-astro
Tree-sitter grammar for astro
-
nixos-unstable 0-unstable-2025-04-23
- nixpkgs-unstable 0-unstable-2025-04-23
- nixos-unstable-small 0-unstable-2025-04-23
pkgs.python312Packages.pytest-astropy-header
Plugin to add diagnostic information to the header of the test output
pkgs.python313Packages.pytest-astropy-header
Plugin to add diagnostic information to the header of the test output
pkgs.python314Packages.pytest-astropy-header
Plugin to add diagnostic information to the header of the test output
pkgs.vimPlugins.nvim-treesitter-parsers.astro
Tree-sitter grammar for astro
-
nixos-unstable 0.0.0+rev=213f6e6
- nixpkgs-unstable 0.0.0+rev=213f6e6
- nixos-unstable-small 0.0.0+rev=213f6e6
pkgs.vscode-extensions.astro-build.astro-vscode
Astro language support for VS Code
pkgs.python313Packages.tree-sitter-grammars.tree-sitter-astro
Python bindings for tree-sitter-astro
-
nixos-unstable 0+unstable20250423
- nixpkgs-unstable 0+unstable20250423
- nixos-unstable-small 0+unstable20250423
pkgs.python314Packages.tree-sitter-grammars.tree-sitter-astro
Python bindings for tree-sitter-astro
-
nixos-unstable 0+unstable20250423
- nixpkgs-unstable 0+unstable20250423
- nixos-unstable-small 0+unstable20250423
Package maintainers
-
@MiniHarinn Harinn <prinn.dev@pm.me>
-
@god464 god464
-
@bdimcheff Brandon Dimcheff <brandon@dimcheff.com>
-
@SuprDewd Bjarki Ágúst Guðmundsson <suprdewd@gmail.com>
-
@kmein Kierán Meinhardt <kmein@posteo.de>
-
@fgaz Francesco Gazzetta <fgaz@fgaz.me>
-
@da-luce Dalton Luce <daltonluce42@gmail.com>
-
@katexochen Paul Meyer <katexochen0@gmail.com>
-
@sikmir Nikolay Korotkiy <sikmir@disroot.org>
-
@sheepforce Phillip Seeber <phillip.seeber@googlemail.com>
-
@returntoreality Linus Karl <linus@lotz.li>
-
@fabaff Fabian Affolter <mail@fabian-affolter.ch>
-
@GaetanLepage Gaetan Lepage <gaetan@glepage.com>
-
@doronbehar Doron Behar <me@doronbehar.com>
-
@KentJames James Kent <jameschristopherkent@gmail.com>
-
@smaret Sébastien Maret <sebastien.maret@icloud.com>
-
@adfaure Adrien Faure <adfaure@pm.me>
-
@A-jay98 Ali Jamadi <ali@jamadi.me>
-
@mightyiam Shahar "Dawn" Or <mightyiampresence@gmail.com>
-
@stepbrobd Yifei Sun <ysun@hey.com>
-
@qweered Aliaksandr Samatyia <grubian2@gmail.com>
-
@DaniD3v DaniD3v <sch220233@spengergasse.at>
-
@uxodb uxodb
-
@aciceri Andrea Ciceri <andrea.ciceri@autistici.org>
-
@RossSmyth Ross Smyth
-
@cherrypiejam Gongqi Huang