PT-2025-48291 · Astro · Astro

Published

2025-11-19

·

Updated

2025-12-11

·

CVE-2025-66202

CVSS v4.0

6.9

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Astro versions 5.15.7 and below
Description Astro, a web framework, is affected by a double URL encoding bypass. This allows unauthenticated attackers to bypass path-based authentication checks in Astro middleware, potentially granting unauthorized access to protected routes. The initial fix in version 5.15.8 was insufficient, as it only decoded URLs once. Attackers can exploit this by using double-encoded URLs to bypass authentication and access routes protected by middleware pathname checks. The vulnerable component is the middleware pathname checks.
Recommendations Update to a version later than 5.15.7.

Exploit

Fix

Path traversal

Weakness Enumeration

Related Identifiers

CVE-2025-66202
GHSA-GGXQ-HP9W-J794
GHSA-WHQG-PPGF-WP8C

Affected Products

Astro