Astro is a web framework. Prior to version 5.15.8, a reflected XSS vulnerability is present when the server islands feature is used in the targeted application, regardless of what was intended by the component template(s). This issue has been patched in version 5.15.8.
History

Thu, 20 Nov 2025 18:00:00 +0000

Type Values Removed Values Added
First Time appeared Astro
Astro astro
CPEs cpe:2.3:a:astro:astro:*:*:*:*:*:node.js:*:*
Vendors & Products Astro
Astro astro

Wed, 19 Nov 2025 21:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 19 Nov 2025 17:00:00 +0000

Type Values Removed Values Added
Description Astro is a web framework. Prior to version 5.15.8, a reflected XSS vulnerability is present when the server islands feature is used in the targeted application, regardless of what was intended by the component template(s). This issue has been patched in version 5.15.8.
Title Astro is vulnerable to Reflected XSS via the server islands feature
Weaknesses CWE-80
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:H/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2025-11-19T16:41:03.767Z

Updated: 2025-11-19T21:07:23.867Z

Reserved: 2025-11-10T22:29:34.877Z

Link: CVE-2025-64764

cve-icon Vulnrichment

Updated: 2025-11-19T21:06:09.025Z

cve-icon NVD

Status : Analyzed

Published: 2025-11-19T17:15:52.647

Modified: 2025-11-20T17:54:05.087

Link: CVE-2025-64764

cve-icon Redhat

No data.