PT-2025-47490 · Astro · @Astrojs/Cloudflare+1

Published

2025-11-19

·

Updated

2025-11-27

·

CVE-2025-65019

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Astro versions prior to 5.15.9
Description Astro, a web framework, has an issue when using the Cloudflare adapter (@astrojs/cloudflare) with output set to 'server'. The image optimization endpoint ('/ image') includes a flaw in the isRemoteAllowed() function. This function incorrectly allows data: protocol URLs, which can be exploited to launch Cross-Site Scripting (XSS) attacks using malicious SVG payloads. This bypasses domain restrictions and Content Security Policy protections.
Recommendations Update to version 5.15.9 or later.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2025-65019
GHSA-FVMW-CJ7J-J39Q

Affected Products

@Astrojs/Cloudflare
Astro