Back to Database
Status published
High
CVE-2025-64764
Astro is vulnerable to Reflected XSS via the server islands feature
Vulnerability Description
Astro is a web framework. Prior to version 5.15.8, a reflected XSS vulnerability is present when the server islands feature is used in the targeted application, regardless of what was intended by the component template(s). This issue has been patched in version 5.15.8.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-64764
Credits & Attribution
No credits recorded in the NVD database.
References
More from withastro
View All →CVE-2025-66202
Astro has an Authentication Bypass via Double URL Encoding, a bypass for CVE-2025-64765
Medium
6.5
CVE-2025-65019
Astro Cloudflare adapter has a Stored Cross Site Scripting vulnerability in /_image endpoint
Medium
5.4
CVE-2025-64765
Astro middleware authentication checks based on url.pathname can be bypassed via url encoded values
Medium
6.9
CVE-2025-64757
Astro Development Server is Vulnerable to Arbitrary Local File Read
Low
3.5
CVE-2025-64745
Astro development server error page vulnerable to reflected Cross-site Scripting
Low
2.7
Affected Vendor
withastro
View all reports →Affected Software
astro
Vulnerable Versions:
< 5.15.8
Timeline
Official Publish:
November 19th, 2025
Last Modified:
November 19th, 2025
Added to House:
July 22nd, 2026
CVSS Vectors
V3:
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:H/A:N