tag sanitization","description":"Astro: XSS in define:vars via incomplete tag sanitization","datePublished":"2026-04-21T20:39:49.000Z","about":{"@type":"Thing","name":"npm astro"},"keywords":"CVE-2026-41067, CVE-2026-41067, npm, astro","isPartOf":{"@id":"https://stateward.com/#website"},"publisher":{"@id":"https://stateward.com/#organization"},"sameAs":["https://nvd.nist.gov/vuln/detail/CVE-2026-41067","https://github.com/advisories/GHSA-j687-52p2-xcff","https://github.com/withastro/astro/security/advisories/GHSA-j687-52p2-xcff","https://github.com/withastro/astro"]}
npm · astro
Astro: XSS in define:vars via incomplete </script> tag sanitization
Is your project exposed to this? Stateward checks every dependency on every pull request and flags it only if your code actually reaches it.
Check my repoSources: CISA KEV (public domain), OSV.dev & GitHub Advisory Database (CC-BY-4.0), FIRST EPSS, NVD/CWE (public domain). Served live from the Stateward advisory database.