Description

Astro is a web framework. Starting in version 5.2.0 and prior to version 5.15.6, a Reflected Cross-Site Scripting (XSS) vulnerability exists in Astro's development server error pages when the `trailingSlash` configuration option is used. An attacker can inject arbitrary JavaScript code that executes in the victim's browser context by crafting a malicious URL. While this vulnerability only affects the development server and not production builds, it could be exploited to compromise developer environments through social engineering or malicious links. Version 5.15.6 fixes the issue.

INFO

Published Date :

2025-11-13T20:26:13.261Z

Last Modified :

2025-11-13T21:20:30.228Z

Source :

GitHub_M
AFFECTED PRODUCTS

The following products are affected by CVE-2025-64745 vulnerability.

Vendors Products
Astro
  • Astro
Withastro
  • Astro

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact