Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-25235 | Astro allows unauthorized third-party images in _image endpoint |
Github GHSA |
GHSA-xf8x-j4p2-f749 | Astro allows unauthorized third-party images in _image endpoint |
Tue, 25 Nov 2025 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Astro
Astro astro |
|
| CPEs | cpe:2.3:a:astro:astro:*:*:*:*:*:node.js:*:* | |
| Vendors & Products |
Astro
Astro astro |
|
| Metrics |
cvssV3_1
|
Thu, 21 Aug 2025 12:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Withastro
Withastro astro |
|
| Vendors & Products |
Withastro
Withastro astro |
Tue, 19 Aug 2025 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 19 Aug 2025 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Astro is a web framework for content-driven websites. In versions of astro before 5.13.2 and 4.16.18, the image optimization endpoint in projects deployed with on-demand rendering allows images from unauthorized third-party domains to be served. On-demand rendered sites built with Astro include an /_image endpoint which returns optimized versions of images. A bug in impacted versions of astro allows an attacker to bypass the third-party domain restrictions by using a protocol-relative URL as the image source, e.g. /_image?href=//example.com/image.png. This vulnerability is fixed in 5.13.2 and 4.16.18. | |
| Title | Unauthorized third-party images in Astro’s _image endpoint | |
| Weaknesses | CWE-115 CWE-79 |
|
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-08-19T20:50:34.071Z
Reserved: 2025-08-12T16:15:30.238Z
Link: CVE-2025-55303
Updated: 2025-08-19T20:49:45.698Z
Status : Analyzed
Published: 2025-08-19T19:15:36.880
Modified: 2025-11-25T14:31:24.007
Link: CVE-2025-55303
No data.
OpenCVE Enrichment
Updated: 2025-08-21T12:31:45Z
EUVD
Github GHSA