Astro-Shield is a library to compute the subresource integrity hashes for your JS scripts and CSS stylesheets. When automated CSP headers generation for SSR content is enabled and the web application serves content that can be partially controlled by external users, then it is possible that the CSP headers generation feature might be "allow-listing" malicious injected resources like inlined JS, or references to external malicious scripts. The fix is available in version 1.3.0.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-1019 | Astro-Shield is a library to compute the subresource integrity hashes for your JS scripts and CSS stylesheets. When automated CSP headers generation for SSR content is enabled and the web application serves content that can be partially controlled by external users, then it is possible that the CSP headers generation feature might be "allow-listing" malicious injected resources like inlined JS, or references to external malicious scripts. The fix is available in version 1.3.0. |
Github GHSA |
GHSA-w387-5qqw-7g8m | Content-Security-Policy header generation in middleware could be compromised by malicious injections |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Fri, 19 Sep 2025 16:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Kindspells
Kindspells astro-shield |
|
| CPEs | cpe:2.3:a:kindspells:astro-shield:1.2.0:*:*:*:*:*:*:* | |
| Vendors & Products |
Kindspells
Kindspells astro-shield |
Sat, 12 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2024-08-02T01:17:58.611Z
Reserved: 2024-03-21T15:12:08.998Z
Link: CVE-2024-29896
Updated: 2024-08-02T01:17:58.611Z
Status : Analyzed
Published: 2024-03-28T13:15:47.717
Modified: 2025-09-19T15:59:51.790
Link: CVE-2024-29896
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA