Threats Tagged 'ghsa-x27w-589x-frm2'
View all threats tagged with 'ghsa-x27w-589x-frm2'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'ghsa-x27w-589x-frm2'
Click on any threat for detailed analysis and mitigation recommendations
Astro: Unauthenticated path override in the @astrojs/vercel ISR function 0 A vulnerability in @astrojs/vercel's ISR function allows unauthenticated attackers to override the rendered path via a query parameter, bypassing edge-level access controls. This affects applications using ISR with protected routes at the edge, enabling attackers to read any GET-rendered route without credentials. The issue arises because the internal ISR function trusts the client-supplied 'x_astro_path' query parameter without authentication, while edge protections only see the ISR path. The vulnerability impacts versions >=10.0.3 and <11.0.3 and has a CVSS score of 6.5 (medium severity). A patch is available to require a secret for path overrides again, restoring the original security boundary. Join the discussion | GCVE Database | 07/20/2026, 23:25:07 UTC Added: 08/08/2026, 14:54:35 UTC |
Showing 1 to 1 of 1 result