PT-2025-47487 · Node.Js+1 · Node.Js+1

Published

2025-11-19

·

Updated

2025-11-19

·

CVE-2025-64757

CVSS v3.1

3.5

Low

VectorAV:A/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Astro versions prior to 5.14.3
Description Astro’s development server has a flaw that allows unauthorized access to local image files. This affects Astro development environments and enables remote attackers to read any image file accessible to the Node.js process on the host system. The issue is related to the image optimization endpoint. The Node.js process is used to serve images.
Recommendations Update to version 5.14.3 or later.

Exploit

Fix

Path traversal

Relative Path Traversal

Weakness Enumeration

Related Identifiers

CVE-2025-64757
GHSA-X3H8-62X9-952G

Affected Products

Astro
Node.Js