Логотип exploitDog
bind:CVE-2025-64745
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2025-64745

Количество 2

Количество 2

nvd логотип

CVE-2025-64745

3 месяца назад

Astro is a web framework. Starting in version 5.2.0 and prior to version 5.15.6, a Reflected Cross-Site Scripting (XSS) vulnerability exists in Astro's development server error pages when the `trailingSlash` configuration option is used. An attacker can inject arbitrary JavaScript code that executes in the victim's browser context by crafting a malicious URL. While this vulnerability only affects the development server and not production builds, it could be exploited to compromise developer environments through social engineering or malicious links. Version 5.15.6 fixes the issue.

CVSS3: 2.7
EPSS: Низкий
github логотип

GHSA-w2vj-39qv-7vh7

3 месяца назад

Astro development server error page is vulnerable to reflected Cross-site Scripting

CVSS3: 2.7
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2025-64745

Astro is a web framework. Starting in version 5.2.0 and prior to version 5.15.6, a Reflected Cross-Site Scripting (XSS) vulnerability exists in Astro's development server error pages when the `trailingSlash` configuration option is used. An attacker can inject arbitrary JavaScript code that executes in the victim's browser context by crafting a malicious URL. While this vulnerability only affects the development server and not production builds, it could be exploited to compromise developer environments through social engineering or malicious links. Version 5.15.6 fixes the issue.

CVSS3: 2.7
0%
Низкий
3 месяца назад
github логотип
GHSA-w2vj-39qv-7vh7

Astro development server error page is vulnerable to reflected Cross-site Scripting

CVSS3: 2.7
0%
Низкий
3 месяца назад

Уязвимостей на страницу