PT-2025-33494 · Astro · Astro

Florian-Lefebvre

·

Published

2025-08-15

·

Updated

2025-08-15

·

CVE-2025-55207

CVSS v4.0

6.9

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N
Name of the Vulnerable Software and Affected Versions: Astro versions prior to 9.4.1
Description: Astro is a web framework for content-driven websites. An open redirect vulnerability exists in certain Astro deployment scenarios. Specifically, when using the Node deployment adapter in standalone mode with trailingSlash set to "always" in the Astro configuration, a crafted URL can redirect users to an external origin. This can lead to potential credential theft, malware distribution, or phishing attacks, as victims may trust the redirected page due to the legitimate-appearing domain. The vulnerability affects any user who clicks on a specially crafted link.
Recommendations: Update to Astro version 9.4.1 or later.

Exploit

Fix

Open Redirect

Weakness Enumeration

Related Identifiers

CVE-2025-55207
GHSA-9X9C-GHC5-JHW9

Affected Products

Astro