Astro < 5.15.8 Reflected Cross-Site Scripting

medium Web App Scanning Plugin ID 115082

Synopsis

Astro < 5.15.8 Reflected Cross-Site Scripting

Description

Astro framework versions prior to 5.15.8 are vulnerable to a Reflected Cross-Site Scripting ...

Solution

Upgrade to Astro 5.15.8 or later.

See Also

https://github.com/withastro/astro/security/advisories/GHSA-wrwg-2hg8-v723

https://zhero-web-sec.github.io/research-and-things/unlocking-reflected-xss-in-the-astro-framework

Plugin Details

Severity: Medium

ID: 115082

Type: remote

Published: 12/17/2025

Updated: 12/17/2025

Scan Template: basic, full, pci, scan

Risk Information

VPR

Risk Factor: Low

Score: 3.3

CVSS v2

Risk Factor: Medium

Base Score: 6.4

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:N

CVSS Score Source: CVE-2025-64764

CVSS v3

Risk Factor: Medium

Base Score: 5.4

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N

CVSS Score Source: CVE-2025-64764

Vulnerability Information

CPE: cpe:2.3:a:astro:astro:*:*:*:*:*:node.js:*:*

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 11/15/2025

Vulnerability Publication Date: 11/18/2025

Reference Information

CVE: CVE-2025-64764