Astro is a web framework for content-driven websites. In versions 3.10.0 through 7.0.3, when a transition:persist, transition:scope, or transition:persist-props directive is applied to a client-hydrated (client:*) component, Astro copied the directive value onto the rendered <astro-island> element without HTML-escaping it. If a developer reflects attacker-controlled input into one of these directives, an attacker can break out of the attribute and inject arbitrary HTML/JavaScript into the server-rendered output, resulting in reflected cross-site scripting (XSS). Exploitation requires the application developer to have written a non-idiomatic pattern — passing untrusted, request-derived input directly into a transition directive. Astro applications that do not route untrusted input into these directives are unaffected. This issue has been fixed in version 7.0.4.
We have discovered 24,608 live websites that are affected by CVE-2026-59727.
| Product | |
| Category | Static Site Generator |
| Vulnerable Domains | 24,608 live websites (93% of Astro install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 313 versions ( 67% of all versions) |
| 14,592 websites | |
| 1,602 websites | |
| 792 websites | |
| 689 websites | |
| 519 websites | |
| 390 websites | |
| 343 websites | |
| 342 websites | |
| 330 websites | |
| 282 websites |
| .com | 11,781 websites |
| .de | 953 websites |
| .org | 898 websites |
| .net | 865 websites |
| .fr | 586 websites |
| .co.uk | 485 websites |
| .io | 398 websites |
| .nl | 328 websites |
| .com.br | 301 websites |
| .pl | 296 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| **********.com | ** | ||
| **.cn | *** | ||
| ************.com | *,*** | ||
| ********.jp | *,*** | ||
| *****.com | *,*** | ||
| ****.**.jp | *,*** | ||
| *******.com | *,*** | ||
| **********.**********.com | *,*** | ||
| ***********.com | *,*** | ||
| *******.io | *,*** |
FAQ