THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-376h-93r7-7g6f (medium) — Astro: Authorization bypass from missing path-segment boundary check when stripping the configured base

[GHSA] GHSA-376h-93r7-7g6f (medium) — Astro: Authorization bypass from missing path-segment boundary check when stripping the configured base

medgithub_advisoriesPublished 2026-09-08

GHSA-376h-93r7-7g6f Severity: medium CVE: CVE-2026-84376

Astro: Authorization bypass from missing path-segment boundary check when stripping the configured base

## Summary

Astro stripped a configured `base` path from request pathnames using a string-prefix check that did not verify a path-segment boundary. With `base: "/app"`, a request to `/appX/admin` was treated as being under the base and r

Indicators of compromise

Original source: https://github.com/advisories/GHSA-376h-93r7-7g6f