OSV 1.4.0 · github-reviewed · 修改于 2026-08-13 04:35
发布时间
2026-07-21 07:26
GitHub 审查时间
2026-07-21 07:26
NVD 发布时间
—
源文件
advisories/github-reviewed/2026/07/GHSA-8mv7-9c27-98vc/GHSA-8mv7-9c27-98vc.json
In the composable astro/hono pipeline, the security.checkOrigin protection is only installed by the middleware() primitive. The actions() and pages() primitives each dispatch to user code independently, so a pipeline that mounts either primitive before (or without) middleware() will bypass the origin check for those requests.
security.checkOrigin (default: true) is intended to reject cross-site POST/PUT/PATCH/DELETE form submissions. In the classic pipeline (astro() all-in-one), the check always runs because Astro injects a virtual middleware module even when the user has no src/middleware.ts. In the composable astro/hono pipeline, the user assembles primitives manually. The check is only installed inside middleware() — so:
actions() before middleware() allows cross-origin form-encoded action requests to execute before the gate runs. The examples/advanced-routing example and the Cloudflare hono docs shipped this order.middleware() entirely (reasonable for apps with no custom middleware) silently drops checkOrigin protection for all on-demand endpoints and pages dispatched through pages().The attack is a blind write-only CSRF: the attacker can trigger a state-mutating action or endpoint handler using the victim's cookies, but cannot read the cross-origin response body.
Astro >= 7.0.0 when using the composable astro/hono pipeline with either:
actions() mounted before middleware(), orpages() used without middleware()The default (non-composable) pipeline is not affected.
The origin check is now applied at each dispatch sink ( and ), gated on , using the same predicate as the middleware. The check is order-independent and a no-op when has already run.
ActionHandler.handlePagesHandler.handleWithErrorFallbackmanifest.checkOriginmiddleware()Ensure middleware() is mounted before both actions() and pages() in the composable pipeline, and that it is always included even when no custom middleware logic is needed:
app.use(middleware());
app.use(actions());
app.use(pages());