CVE-2025-59837

Astro is a web framework that includes an image proxy. In versions 5.13.4 and later before 5.13.10, the image proxy domain validation can be bypassed by using backslashes in the href parameter, allowing server-side requests to arbitrary URLs. This can lead to server-side request forgery (SSRF) and potentially cross-site scripting (XSS). This vulnerability exists due to an incomplete fix for CVE-2025-58179. Fixed in 5.13.10.
Configurations

Configuration 1 (hide)

cpe:2.3:a:astro:astro:*:*:*:*:*:node.js:*:*

History

25 Nov 2025, 15:16

Type Values Removed Values Added
References () https://github.com/withastro/astro/commit/1e2499e8ea83ebfa233a18a7499e1ccf169e56f4 - () https://github.com/withastro/astro/commit/1e2499e8ea83ebfa233a18a7499e1ccf169e56f4 - Patch
References () https://github.com/withastro/astro/commit/9ecf3598e2b29dd74614328fde3047ea90e67252 - () https://github.com/withastro/astro/commit/9ecf3598e2b29dd74614328fde3047ea90e67252 - Patch
References () https://github.com/withastro/astro/security/advisories/GHSA-qcpr-679q-rhm2 - () https://github.com/withastro/astro/security/advisories/GHSA-qcpr-679q-rhm2 - Exploit, Third Party Advisory
First Time Astro astro
Astro
CPE cpe:2.3:a:astro:astro:*:*:*:*:*:node.js:*:*

Information

Published : 2025-10-28 20:15

Updated : 2025-11-25 15:16


NVD link : CVE-2025-59837

Mitre link : CVE-2025-59837

CVE.ORG link : CVE-2025-59837


JSON object : View

Products Affected

astro

  • astro
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CWE-918

Server-Side Request Forgery (SSRF)