@astrojs/vercel
npm2 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting @astrojs/vercelpage 1 of 1
- CVE-2026-33768CRITICALCVSS 9.1EG 9.1✓ Fixed in 10.0.22026-03-24
Astro is a web framework. Prior to version 10.0.2, the @astrojs/vercel serverless entrypoint reads the x-astro-path header and x_astro_path query parameter to rewrite the internal request path, with no authentication whatsoever. On deploym…
- CVE-2026-73424MEDIUMCVSS 6.5EG 6.5✓ Fixed in 11.0.32026-08-17
Astro is a web framework for content-driven websites. From 10.0.3 until 11.0.3, the Astro Vercel adapter in packages/integrations/vercel/src/serverless/entrypoint.ts accepts x_astro_path for the public /_isr function based only on the x-ve…
Check whether @astrojs/vercel is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for @astrojs/vercel CVEs against the assets you own.
Start Free Scan →