CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-59727

lowcovered by 2 sourcesfirst seen 2026-07-20
Summary When a transition:persist, transition:scope, or transition:persist-props directive is applied to a client-hydrated (client:*) component, Astro copied the directive value onto the rendered <astro-island> element without HTML-escaping it. If a developer reflects attacker-controlled input into one of these directives, an attacker can break out of the attribute and inject arbitrary HTML/JavaScript into the server-rendered output, resulting in reflected cross-site scripting (XSS). Severity Although a generic reflected XSS scores in the Medium range, exploitation here requires the application developer to have written a non-idiomatic pattern — passing untrusted, request-derived input directly into a transition directive. Astro applications that do not route untrusted input into these directives are unaffected. This mitigating precondition places the real-world severity at Low. Details In generateHydrateScript() (packages/astro/src/runtime/server/hydration.ts), every island property is HTML-escaped before serialization — the attrs, props, and opts assignments all pass through escapeHTML(). The transition directives, however, were copied verbatim: transitionDirectivesToCopyOnIsland.forEach((name) => { if (typeof props[name] !== 'undefined') { island.props[name] = props[name]; // not escaped } }); The <astro-island> element is serialized via renderElement('astro-island', island, false) with shouldEscape=false, and toAttributeString() returns the value unchanged in that mode. As a result there is no downstream re-escaping, and the raw directive value reaches the HTML response. This is the same output sink previously addressed for slot names in GHSA-8hv8-536x-4wqp. The affected directives are: - data-astro-transition-scope (transition:scope) - data-astro-transition-persist (transition:persist) - data-astro-transition-persist-props (transition:persist-props) Note that transition:persist is typed boolean | string, so passing a string value is a supported use of

⚡ Watch CVE-2026-59727

Get an email if CVE-2026-59727 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Exploitation outlook

Advisory coverage (2)

External references

NVD record for CVE-2026-59727

CVE.org record

Embed the live status

CVE-2026-59727 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-59727 status](https://www.csirts.com/badge/CVE-2026-59727)](https://www.csirts.com/cve/CVE-2026-59727)