CVE 3.5 LOW

Astro Development Server is Vulnerable to Arbitrary Local File Read_CVE-2025-64757

3.5 / 10
LOW
CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N

Description

Astro is a web framework. Prior to version 5.14.3, a vulnerability has been identified in the Astro framework's development server that allows arbitrary local file read access through the image optimization endpoint. The vulnerability affects Astro development environments and allows remote attackers to read any image file accessible to the Node.js process on the host system. This issue has been patched in version 5.14.3.

Basic Information

ID CVE-2025-64757
Source GitHub_M
Published Nov 19, 2025 at 16:40
Modified Nov 19, 2025 at 21:04

Affected Product

Vendor withastro
Product astro
Version < 5.14.3
Affected Versions withastro astro < 5.14.3

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.