PT-2025-47488 · Astro · Astro

Published

2025-11-19

·

Updated

2026-05-13

·

CVE-2025-64764

CVSS v3.1

7.1

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:L/I:H/A:N
Name of the Vulnerable Software and Affected Versions Astro versions prior to 5.15.8
Description A reflected cross-site scripting (XSS) issue exists in Astro when the server islands feature is utilized. The issue affects applications using the server islands feature, regardless of the component template's intended behavior.
Recommendations Update to version 5.15.8 or later.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2025-64764
GHSA-WRWG-2HG8-V723

Affected Products

Astro