Aller au contenu

Fiche vulnérabilité

CVE-2025-64764 : faille moyenne astro astro (CVSS 5.4)

Description

Astro is a web framework. Prior to version 5.15.8, a reflected XSS vulnerability is present when the server islands feature is used in the targeted application, regardless of what was intended by the component template(s). This issue has been patched in version 5.15.8.

En bref

Sévérité
Moyenne (CVSS 5.4)
Vecteur CVSS
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
Exploitation active
Non signalée par la CISA
Publication
19 nov. 2025
Dernière mise à jour
17 juin 2026

Produits concernés

  • astro astro

Références

Rechercher une autre vulnérabilité dans la base CVE