HIGH🇵🇱 Wersja polska

CVE-2025-64764

CVSS 7.1v3.1pub. 2025-11-19upd. 2025-11-20

Astro is a web framework. Prior to version 5.15.8, a reflected XSS vulnerability is present when the server islands feature is used in the targeted application, regardless of what was intended by the component template(s). This issue has been patched in version 5.15.8.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:H/A:N
  • Astro

    APP
    Astro
    < 5.15.8
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
XSS
CWE
References

Related vulnerabilities

CVE-2026-54299HIGH7.5same product

Astro is a web framework. Prior to 6.4.6, Astro SSR apps with prerendered error pages (/404 or /500 using expo...

CVE-2026-50146HIGH7.1same product

Astro is a web framework. Prior to 6.3.3, when a component uses a client:* directive, Astro inserts named slot...

CVE-2025-59837HIGH7.2same product

Astro is a web framework that includes an image proxy. In versions 5.13.4 and later before 5.13.10, the image ...

CVE-2024-56159HIGH7.8same product

Astro is a web framework for content-driven websites. A bug in the build process allows any unauthenticated us...

CVE-2026-54298MEDIUM4.2same product

Astro to framework webowy. Przed wersją 6.4.6 funkcja spreadAttributes w pipeline'u server-side renderingu Ast...