Known CVE
Astro - Unauthorized Third-Party Image Access
Astro < 5.13.2 and < 4.16.18 contains an information disclosure vulnerability caused by improper validation of protocol-relative URLs in the image optimization endpoint, letting attackers serve images from unauthorized third-party domains, exploit requires on-demand rendering deployment.
CVE-2025-55303
Medium2025CVSS 6.4CWE-79
cve2025 · astro · ssrf · vuln · vkev
Verified scans run this check after you prove you own the site.
All known CVEsView the checks catalogNational Vulnerability Database
Scan a website