Skip to content

Known CVE

Astro - Unauthorized Third-Party Image Access

Astro < 5.13.2 and < 4.16.18 contains an information disclosure vulnerability caused by improper validation of protocol-relative URLs in the image optimization endpoint, letting attackers serve images from unauthorized third-party domains, exploit requires on-demand rendering deployment.

CVE-2025-55303

Medium2025CVSS 6.4CWE-79

cve2025 · astro · ssrf · vuln · vkev

Verified scans run this check after you prove you own the site.

All known CVEsView the checks catalogNational Vulnerability Database

Scan a website