PT-2025-33494 · Astro · Astro
Florian-Lefebvre
·
Published
2025-08-15
·
Updated
2025-08-15
·
CVE-2025-55207
CVSS v4.0
6.9
Medium
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N |
Name of the Vulnerable Software and Affected Versions:
Astro versions prior to 9.4.1
Description:
Astro is a web framework for content-driven websites. An open redirect vulnerability exists in certain Astro deployment scenarios. Specifically, when using the Node deployment adapter in standalone mode with
trailingSlash set to "always" in the Astro configuration, a crafted URL can redirect users to an external origin. This can lead to potential credential theft, malware distribution, or phishing attacks, as victims may trust the redirected page due to the legitimate-appearing domain. The vulnerability affects any user who clicks on a specially crafted link.Recommendations:
Update to Astro version 9.4.1 or later.
Exploit
Fix
Open Redirect
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Astro