Astro is a web framework. Prior to version 5.14.3, a vulnerability has been identified in the Astro framework's development server that allows arbitrary local file read access through the image optimization endpoint. The vulnerability affects Astro development environments and allows remote attackers to read any image file accessible to the Node.js process on the host system. This issue has been patched in version 5.14.3.
History

Thu, 20 Nov 2025 18:00:00 +0000

Type Values Removed Values Added
First Time appeared Astro
Astro astro
CPEs cpe:2.3:a:astro:astro:*:*:*:*:*:node.js:*:*
Vendors & Products Astro
Astro astro

Wed, 19 Nov 2025 22:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 19 Nov 2025 17:00:00 +0000

Type Values Removed Values Added
Description Astro is a web framework. Prior to version 5.14.3, a vulnerability has been identified in the Astro framework's development server that allows arbitrary local file read access through the image optimization endpoint. The vulnerability affects Astro development environments and allows remote attackers to read any image file accessible to the Node.js process on the host system. This issue has been patched in version 5.14.3.
Title Astro Development Server is Vulnerable to Arbitrary Local File Read
Weaknesses CWE-22
CWE-23
References
Metrics cvssV3_1

{'score': 3.5, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2025-11-19T16:40:36.031Z

Updated: 2025-11-19T21:04:23.556Z

Reserved: 2025-11-10T22:29:34.875Z

Link: CVE-2025-64757

cve-icon Vulnrichment

Updated: 2025-11-19T21:04:20.345Z

cve-icon NVD

Status : Analyzed

Published: 2025-11-19T17:15:52.460

Modified: 2025-11-20T17:58:21.573

Link: CVE-2025-64757

cve-icon Redhat

No data.