网安资讯详情 - SecLens 情报雷达

网安资讯,一网打尽。汇集权威漏洞通告与行业要闻,结合分组浏览、智能过滤、RSS订阅 和 Webhook 推送,多通道拓展您的安全情报视野。

npm/astro: Astro: composable `astro/hono` pipeline bypasses `security.checkOrigin` when `middleware()` is absent or misordered

来源: github_advisory · 发布时间 2026-07-21 07:26 (UTC+08:00) · 抓取时间 2026-07-21 07:45 (UTC+08:00)

原文链接

摘要

Severity: MEDIUM | Package: npm/astro | Affected: >= 7.0.0, < 7.0.6 | Patched: 7.0.6

正文

## Summary In the composable `astro/hono` pipeline, the `security.checkOrigin` protection is only installed by the `middleware()` primitive. The `actions()` and `pages()` primitives each dispatch to user code independently, so a pipeline that mounts either primitive before (or without) `middleware()` will bypass the origin check for those requests. ## Details `security.checkOrigin` (default: `true`) is intended to reject cross-site `POST`/`PUT`/`PATCH`/`DELETE` form submissions. In the classic pipeline (`astro()` all-in-one), the check always runs because Astro injects a virtual middleware module even when the user has no `src/middleware.ts`. In the composable `astro/hono` pipeline, the user assembles primitives manually. The check is only installed inside `middleware()` — so: - Mounting `actions()` before `middleware()` allows cross-origin form-encoded action requests to execute before the gate runs. The `examples/advanced-routing` example and the Cloudflare `hono` docs shipped this order. - Omitting `middleware()` entirely (reasonable for apps with no custom middleware) silently drops `checkOrigin` protection for all on-demand endpoints and pages dispatched through `pages()`. The attack is a blind write-only CSRF: the attacker can trigger a state-mutating action or endpoint handler using the victim's cookies, but cannot read the cross-origin response body. ## Affected versions Astro `>= 7.0.0` when using the composable `astro/hono` pipeline with either: - `actions()` mounted before `middleware()`, or - `pages()` used without `middleware()` The default (non-composable) pipeline is not affected. ## Fix The origin check is now applied at each dispatch sink (`ActionHandler.handle` and `PagesHandler.handleWithErrorFallback`), gated on `manifest.checkOrigin`, using the same predicate as the middleware. The check is order-independent and a no-op when `middleware()` has already run. Fix: https://github.com/withastro/astro/pull/17250 ## Workaround Ensure `middleware()` is mounted before both `actions()` and `pages()` in the composable pipeline, and that it is always included even when no custom middleware logic is needed: ```ts app.use(middleware()); app.use(actions()); app.use(pages()); ```

标签

扩展字段

{
  "credits": [
    {
      "login": "jlgore",
      "type": "reporter"
    }
  ],
  "cwe_ids": [
    "CWE-352"
  ],
  "cwe_names": [
    "Cross-Site Request Forgery (CSRF)"
  ],
  "ghsa_id": "GHSA-8mv7-9c27-98vc",
  "package": {
    "ecosystem": "npm",
    "name": "astro",
    "patched_version": "7.0.6",
    "vulnerable_range": ">= 7.0.0, < 7.0.6"
  },
  "references": [
    "https://github.com/withastro/astro/security/advisories/GHSA-8mv7-9c27-98vc",
    "https://github.com/withastro/astro/pull/17250",
    "https://github.com/withastro/astro/commit/0b30b35f864310bee8485c952d1877e82e2b9b1a",
    "https://github.com/withastro/astro/releases/tag/[email protected]",
    "https://github.com/advisories/GHSA-8mv7-9c27-98vc"
  ],
  "source_code_location": "https://github.com/withastro/astro",
  "updated_at": "2026-07-20T23:26:28Z"
}