Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

6 advisories

Loading
Atro CSRF Middleware Bypass (security.checkOrigin) Moderate
CVE-2024-56140 was published for astro (npm) Dec 18, 2024
KageShiron Credited to KageShiron, ematipico, delucis, and ascorbic ematipico ematipico
delucis delucis ascorbic ascorbic
Astros's duplicate trailing slash feature leads to an open redirection security issue Moderate
CVE-2025-54793 was published for astro (npm) Aug 7, 2025
ghiyastfarisi Credited to ghiyastfarisi, ascorbic, and ematipico ascorbic ascorbic
ematipico ematipico
@astrojs/node's trailing slash handling causes open redirect issue Moderate
CVE-2025-55207 was published for @astrojs/node (npm) Aug 15, 2025
florian-lefebvre Credited to florian-lefebvre, ematipico, Fryuni, and delucis ematipico ematipico
Fryuni Fryuni delucis delucis
Astro allows unauthorized third-party images in _image endpoint Moderate
CVE-2025-55303 was published for @astrojs/node (npm) Aug 19, 2025
HakuPiku Credited to HakuPiku, GeneralZero, chriselbring-avalabs, ematipico, delucis, and Princesseuh GeneralZero GeneralZero
chriselbring-avalabs chriselbring-avalabs ematipico ematipico delucis delucis Princesseuh Princesseuh
Server-Side Request Forgery via /_image endpoint in Astro Cloudflare adapter High
CVE-2025-58179 was published for @astrojs/cloudflare (npm) Sep 4, 2025
ghostdevv Credited to ghostdevv, monizb, alexanderniebuhr, ascorbic, ematipico, and delucis monizb monizb
alexanderniebuhr alexanderniebuhr ascorbic ascorbic ematipico ematipico delucis delucis
Astro Development Server has Arbitrary Local File Read Low
CVE-2025-64757 was published for astro (npm) Nov 19, 2025
monizb Credited to monizb, Princesseuh, delucis, and ematipico Princesseuh Princesseuh
delucis delucis ematipico ematipico
ProTip! Advisories are also available from the GraphQL API