CVE 2.7 LOW

Astro development server error page vulnerable to reflected Cross-site Scripting_CVE-2025-64745

2.7 / 10
LOW
CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:C/C:L/I:N/A:N

Description

Astro is a web framework. Starting in version 5.2.0 and prior to version 5.15.6, a Reflected Cross-Site Scripting (XSS) vulnerability exists in Astro's development server error pages when the `trailingSlash` configuration option is used. An attacker can inject arbitrary JavaScript code that executes in the victim's browser context by crafting a malicious URL. While this vulnerability only affects the development server and not production builds, it could be exploited to compromise developer environments through social engineering or malicious links. Version 5.15.6 fixes the issue.

Basic Information

ID CVE-2025-64745
Source GitHub_M
Published Nov 13, 2025 at 20:26
Modified Nov 13, 2025 at 21:20

Affected Product

Vendor withastro
Product astro
Version >= 5.2.0, < 5.15.6
Affected Versions withastro astro >= 5.2.0, < 5.15.6

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.