CVE Database · CVE-2025-64764
CVSS v3.1
7.1
EPSS
0.50%
Published
Nov 19, 2025
Modified
Nov 20, 2025
Public PoC / Exploit (2)
All weaponized →Links to public security research (Exploit-DB, Nuclei, Trickest, GitHub) for defensive use only.
Description
Astro is a web framework. Prior to version 5.15.8, a reflected XSS vulnerability is present when the server islands feature is used in the targeted application, regardless of what was intended by the component template(s). This issue has been patched in version 5.15.8.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:H/A:NWeaknesses (CWE)
Affected Products (1)
References (2)