Security Advisory

CVE-2025-59837

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2025-10-28 19:54:28
Last updated 2025-10-29 17:42:43
Assigner GitHub_M
State PUBLISHED

Description

Astro is a web framework that includes an image proxy. In versions 5.13.4 and later before 5.13.10, the image proxy domain validation can be bypassed by using backslashes in the href parameter, allowing server-side requests to arbitrary URLs. This can lead to server-side request forgery (SSRF) and potentially cross-site scripting (XSS). This vulnerability exists due to an incomplete fix for CVE-2025-58179. Fixed in 5.13.10.