CVE-2026-33768: 
JavaScript vulnerability analysis and mitigation

Overview

CVE-2026-33768 is an unauthenticated path override vulnerability in the @astrojs/vercel serverless adapter for the Astro web framework. The flaw allows any unauthenticated attacker to rewrite the internal request path processed by the serverless entrypoint by supplying the x-astro-path HTTP header or x_astro_path query parameter, effectively bypassing Vercel's platform-level firewall and path-based access controls. All versions of @astrojs/vercel prior to 10.0.2 are affected (verified against Astro 5.18.1 + @astrojs/vercel 9.0.4 and Astro 6.0.3 + @astrojs/vercel 10.0.0). The vulnerability was published on March 24, 2026, and patched in version 10.0.2 released March 19, 2026. The CVSS v3.1 base score is 6.5 (Moderate) per the GitHub Advisory, though Feedly's NVD data assigns a higher score of 9.1 (Critical) reflecting the full confidentiality and integrity impact (GitHub Advisory, Github Advisory).

Technical details

The root cause is a missing authorization check (CWE-862) combined with an unintended proxy/confused deputy pattern (CWE-441) in packages/integrations/vercel/src/serverless/entrypoint.ts. The vulnerable code unconditionally reads the x-astro-path header or x_astro_path query parameter and rewrites url.pathname without verifying the trusted middlewareSecret — a check that was already applied to the adjacent x-astro-locals header. The x-astro-path mechanism was designed for internal use by Vercel Edge Middleware (which always overwrites any client-supplied value), but when no Edge Middleware is configured, the serverless function is directly reachable and the override is fully attacker-controlled. Because the rewritten request preserves the original HTTP method and body, all methods (GET, POST, PUT, DELETE) are affected; Vercel's firewall evaluates the original path while the serverless function serves the overridden one (GitHub Advisory, Patch Commit).

Impact

An unauthenticated remote attacker can bypass all path-based firewall rules, IP blocks, geo-restrictions, and rate limits configured in Vercel Dashboard or vercel.json, gaining read access to any protected page or API endpoint and write access to any restricted mutation endpoint (POST/PUT/DELETE). This means administrative functions (e.g., user deletion, data modification) that are protected solely by path-based firewall rules are fully reachable. Additionally, Vercel audit logs record the original (spoofed) path rather than the actually-served path, creating an audit log mismatch that makes detection difficult without specific knowledge of the x_astro_path parameter (GitHub Advisory).

Exploitability

A proof-of-concept exploit consisting of concrete curl commands is publicly available in the official GitHub Security Advisory, demonstrating full exploitation against real Astro/Vercel deployments (GitHub Advisory). No privileges, authentication, or user interaction are required; the attack is executable over the network with low complexity. The EPSS score is approximately 0.05% (16th percentile), and there is no evidence of in-the-wild exploitation or threat actor attribution at this time. The vulnerability is not listed in the CISA KEV catalog.

Exploitation steps

  1. Reconnaissance: Identify Astro SSR deployments on Vercel using @astrojs/vercel adapter versions prior to 10.0.2 without Edge Middleware configured. Look for publicly accessible Vercel-hosted sites built with Astro (e.g., via response headers or vercel.json artifacts).
  2. Identify a public endpoint: Find any publicly accessible route (e.g., /public, /api/health) that is not blocked by Vercel's firewall and can serve as the "cover" path for the override.
  3. Identify a restricted target path: Determine a protected path (e.g., /admin/secret, /admin/delete-user) that is blocked by Vercel's firewall or path-based access controls.
  4. Bypass firewall via GET override: Send a GET request to the public endpoint with the x_astro_path query parameter set to the restricted path:
    curl "https://target.vercel.app/public?x_astro_path=/admin/secret"
    # Returns: PAGE_ID: admin-secret
    Alternatively, use the header form:
    curl -H "x-astro-path: /admin/secret" https://target.vercel.app/public
  5. Execute write operations via POST override (verified on Astro 5.x): Send a POST request with body to a public endpoint, overriding the path to a protected mutation endpoint:
    curl -X POST -H "Content-Type: application/json" -d '{"userId":"123"}' \
      "https://target.vercel.app/api/health?x_astro_path=/admin/delete-user"
    # Returns: {"action":"delete-user","status":"deleted","method":"POST"}
  6. Achieve objective: The serverless function processes the request against the overridden path with the original method and body, while Vercel's firewall only evaluated the original (public) path — granting full access to the restricted resource (GitHub Advisory).

Indicators of compromise

  • Network: HTTP requests to public/non-sensitive endpoints (e.g., /public, /api/health) containing the x_astro_path query parameter or x-astro-path header pointing to sensitive paths (e.g., /admin/*); unexpected HTTP methods (POST, PUT, DELETE) to endpoints that normally only receive GET requests.
  • Logs: Vercel access logs showing requests like GET /public?x_astro_path=/admin/secret or POST /api/health?x_astro_path=/admin/delete-user — the logged path will be the public endpoint, not the actually-served restricted path; discrepancies between logged paths and actual application behavior.
  • Application Behavior: Unexpected responses from public endpoints (e.g., admin page content or admin API responses returned for requests to non-admin paths); unauthorized data modifications (deletions, updates) with no corresponding direct requests to admin endpoints in logs (GitHub Advisory).

Mitigation and workarounds

Upgrade @astrojs/vercel to version 10.0.2 or later, which gates path override processing behind the trusted middlewareSecret — the same secret already protecting x-astro-locals (Patch Commit, Release Notes). For deployments unable to patch immediately, implement Vercel Edge Middleware (which always overwrites any client-supplied x-astro-path value with the correct one), or configure reverse proxy/WAF rules to block or strip requests containing the x-astro-path header or x_astro_path query parameter before they reach the serverless function. ISR (Incremental Static Regeneration) deployments are not affected, as Vercel's cache layer intercepts before the function runs (GitHub Advisory).

Community reactions

The vulnerability was reported by security researcher jp-soba and published by Astro maintainer matthewp on March 24, 2026. The advisory explicitly draws a parallel to CVE-2025-29927 (Next.js x-middleware-subrequest header bypass), highlighting this as a recurring class of vulnerability in serverless web framework adapters where internal routing headers are exposed to external callers. The fix was merged on March 19, 2026 (before public disclosure), though it introduced a regression in ISR path rewriting that required a follow-up fix in PR #16079 (GitHub Advisory, Fix PR).

Additional resources


Source: This report was generated using AI

Related JavaScript vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

GHSA-w2vw-w76x-qr89HIGH8.5
  • JavaScript logoJavaScript
  • nx
NoYesOct 05, 2026
CVE-2026-104852HIGH8.2
  • JavaScript logoJavaScript
  • @graphql-tools/utils
NoYesOct 05, 2026
GHSA-g7fw-3gjp-g5hfMEDIUM6.5
  • JavaScript logoJavaScript
  • @openclaw/matrix
NoYesOct 05, 2026
GHSA-r4xh-jqrq-34v2MEDIUM5.3
  • JavaScript logoJavaScript
  • smol-toml
NoYesOct 05, 2026
GHSA-6688-9rhm-gjv2LOWN/A
  • JavaScript logoJavaScript
  • dompurify
NoYesOct 05, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management