Astro是Astro开源的一个内容驱动网站的 web 框架。 Astro 5.15.8之前版本存在路径遍历漏洞,该漏洞源于路径规范化不一致,可能导致绕过验证检查访问受保护路由。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2025-64764 | 7.1 HIGH | Astro is vulnerable to Reflected XSS via the server islands feature |
| CVE-2025-65019 | 5.4 MEDIUM | Astro Cloudflare adapter has a Stored Cross Site Scripting vulnerability in /_image endpoi |
| CVE-2025-64757 | 3.5 LOW | Astro Development Server is Vulnerable to Arbitrary Local File Read |
No comments yet