tag sanitization", "url": "https://ghostwire.news/cve/CVE-2026-41067", "datePublished": "2026-04-21T20:39:49.000Z", "dateModified": "2026-04-21T20:39:52.000Z", "publisher": {"@type": "Organization", "name": "Ghostwire", "url": "https://ghostwire.news"}, "about": { "@type": "SoftwareApplication", "name": "CVE-2026-41067", "applicationCategory": "SecurityVulnerability" }, "proficiencyLevel": "Expert" }
Ghostwire

CVE-2026-41067: Astro: XSS in define:vars via incomplete </script> tag sanitization

MEDIUM CVSS 6.1 Exploit Available

Published: April 21, 2026 | Last Modified: April 21, 2026

Description

Astro: XSS in define:vars via incomplete </script> tag sanitization

Ghostwire Analysis — What This Means Practically

This analysis is generated by Ghostwire from NVD, CISA KEV, EPSS, and open-source intelligence data. Verify findings through primary sources before acting.

References