{"id":"CVE-2026-73423","aliases":["GHSA-8mv7-9c27-98vc"],"url":"https://o3.security/vulnerability/CVE-2026-73423","summary":"Astro: composable `astro/hono` pipeline bypasses `security.checkOrigin` when `middleware()` is absent or misordered","details":"## Summary\n\nIn the composable `astro/hono` pipeline, the `security.checkOrigin` protection is only installed by the `middleware()` primitive. The `actions()` and `pages()` primitives each dispatch to user code independently, so a pipeline that mounts either primitive before (or without) `middleware()` will bypass the origin check for those requests.\n\n## Details\n\n`security.checkOrigin` (default: `true`) is intended to reject cross-site `POST`/`PUT`/`PATCH`/`DELETE` form submissions. In the classic pipeline (`astro()` all-in-one), the check always runs because Astro injects a virtual middleware module even when the user has no `src/middleware.ts`. In the composable `astro/hono` pipeline, the user assembles primitives manually. The check is only installed inside `middleware()` — so:\n\n- Mounting `actions()` before `middleware()` allows cross-origin form-encoded action requests to execute before the gate runs. The `examples/advanced-routing` example and the Cloudflare `hono` docs shipped this order.\n- Omitting `middleware()` entirely (reasonable for apps with no custom middleware) silently drops `checkOrigin` protection for all on-demand endpoints and pages dispatched through `pages()`.\n\nThe attack is a blind write-only CSRF: the attacker can trigger a state-mutating action or endpoint handler using the victim's cookies, but cannot read the cross-origin response body.\n\n## Affected versions\n\nAstro `>= 7.0.0` when using the composable `astro/hono` pipeline with either:\n- `actions()` mounted before `middleware()`, or\n- `pages()` used without `middleware()`\n\nThe default (non-composable) pipeline is not affected.\n\n## Fix\n\nThe origin check is now applied at each dispatch sink (`ActionHandler.handle` and `PagesHandler.handleWithErrorFallback`), gated on `manifest.checkOrigin`, using the same predicate as the middleware. The check is order-independent and a no-op when `middleware()` has already run.\n\nFix: https://github.com/withastro/astro/pull/17250\n\n## Workaround\n\nEnsure `middleware()` is mounted before both `actions()` and `pages()` in the composable pipeline, and that it is always included even when no custom middleware logic is needed:\n\n```ts\napp.use(middleware());\napp.use(actions());\napp.use(pages());\n```","published":"2026-08-12T20:35:32.181Z","modified":"2026-09-11T03:30:50.966993679Z","cvss":null,"epss":{"score":0.00182,"percentile":0.08082,"asOf":"2026-09-17"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"npm","name":"astro","fixedVersion":"7.0.6"}],"fix":{"url":"https://github.com/withastro/astro/commit/0b30b35f864310bee8485c952d1877e82e2b9b1a","label":"withastro/astro@0b30b35"},"references":[{"type":"WEB","url":"https://github.com/withastro/astro/releases/tag/astro@7.0.6"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/73xxx/CVE-2026-73423.json"},{"type":"ADVISORY","url":"https://github.com/withastro/astro/security/advisories/GHSA-8mv7-9c27-98vc"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-73423"},{"type":"FIX","url":"https://github.com/withastro/astro/commit/0b30b35f864310bee8485c952d1877e82e2b9b1a"},{"type":"FIX","url":"https://github.com/withastro/astro/pull/17250"},{"type":"PACKAGE","url":"https://github.com/withastro/astro"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-09-11T03:30:50.966993679Z"}}