CVE-2026-33768 | withastro up to 10.0.1 Query Parameter x_astro_path confused deputy (GHSA-mr6q-rp88-fx84 / EUVD-2026-14982)
A vulnerability classified as critical was found in withastro astro up to 10.0.1. The affected element is an unknown function of the component Query Parameter Handler. The manipulation of the argument x_astro_path results in unintended intermediary.
This vulnerability is reported as CVE-2026-33768. The attack can be launched remotely. No exploit exists.
Upgrading the affected component is advised.