CVE-2026-41067 | withastro up to 6.1.5 HTML Parser defineScriptVars HTML injection (GHSA-j687-52p2-xcff)
A vulnerability was found in withastro astro up to 6.1.5. It has been classified as problematic. This impacts the function defineScriptVars of the component HTML Parser. Performing a manipulation results in HTML injection.
This vulnerability is identified as CVE-2026-41067. The attack can be initiated remotely. There is not any exploit available.
Upgrading the affected component is recommended.