THREAT OPS › Threat News › [GHSA] GHSA-376h-93r7-7g6f (medium) — Astro: Authorization bypass from missing path-segment boundary check when stripping the configured base
[GHSA] GHSA-376h-93r7-7g6f (medium) — Astro: Authorization bypass from missing path-segment boundary check when stripping the configured base
GHSA-376h-93r7-7g6f Severity: medium CVE: CVE-2026-84376
Astro: Authorization bypass from missing path-segment boundary check when stripping the configured base
## Summary
Astro stripped a configured `base` path from request pathnames using a string-prefix check that did not verify a path-segment boundary. With `base: "/app"`, a request to `/appX/admin` was treated as being under the base and r
Indicators of compromise
- CVE-2026-84376cve
Original source: https://github.com/advisories/GHSA-376h-93r7-7g6f