CVE-2025-59837High· 7.2▾ TwilightAstro is a web framework that includes an image proxy. In versions 5.13.4 and later before 5.13.10, the image proxy domain validation can be bypassed by using backslashes in the href parameter, allowing server-side requests to arbitrary …
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 39.6 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.4%
Astro is a web framework that includes an image proxy. In versions 5.13.4 and later before 5.13.10, the image proxy domain validation can be bypassed by using backslashes in the href parameter, allowing server-side requests to arbitrary URLs. This can lead to server-side request forgery (SSRF) and potentially cross-site scripting (XSS). This vulnerability exists due to an incomplete fix for CVE-2025-58179. Fixed in 5.13.10.
astro >= 5.13.4, < 5.13.10Upgrade past the affected range:
astro 5.13.10Connected by shared product, vendor, weakness, or advisory.
CVE-2025-64525Medium· 6.5Astro is a web framework
CVE-2026-102983Medium· 6.3Astro is a web framework for content-driven websites
CVE-2026-59727LowAstro: Cross-site scripting via unescaped transition:* directive values on hydrated islands
CVE-2026-59729MediumAstro: XSS via unescaped spread attribute names in renderHTMLElement (incomplete fix for CVE-2026-54298)
GHSA-4g3v-8h47-v7g6MediumAstro: Reflected XSS via unescaped View Transition animation properties
CVE-2026-50146High· 7.1Astro: Reflected XSS via unescaped slot name