Astro is a web framework that includes an image proxy. In versions 5.13.4 and later before 5.13.10, the image proxy domain validation can be bypassed by using backslashes in the href parameter, allowing server-side requests to arbitrary URLs. This can lead to server-side request forgery (SSRF) and potentially cross-site scripting (XSS). This vulnerability exists due to an incomplete fix for CVE-2025-58179. Fixed in 5.13.10.
Metrics
Affected Vendors & Products
References
History
Tue, 28 Oct 2025 20:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Astro is a web framework that includes an image proxy. In versions 5.13.4 and later before 5.13.10, the image proxy domain validation can be bypassed by using backslashes in the href parameter, allowing server-side requests to arbitrary URLs. This can lead to server-side request forgery (SSRF) and potentially cross-site scripting (XSS). This vulnerability exists due to an incomplete fix for CVE-2025-58179. Fixed in 5.13.10. | |
| Title | astro allows bypass of image proxy domain validation leading to SSRF and potential XSS | |
| Weaknesses | CWE-79 CWE-918 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published: 2025-10-28T19:54:28.683Z
Updated: 2025-10-28T19:54:28.683Z
Reserved: 2025-09-22T14:34:03.471Z
Link: CVE-2025-59837
No data.
Status : Received
Published: 2025-10-28T20:15:49.170
Modified: 2025-10-28T20:15:49.170
Link: CVE-2025-59837
No data.