HIGH 7.2 npm
Astro's bypass of image proxy domain validation leads to SSRF and potential XSS
GHSA-qcpr-679q-rhm2 · CVE-2025-59837
Published · Modified
AI SAST
Find this class of vulnerability in your own code
Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.
Description
Summary
This is a patch bypass of CVE-2025-58179 in commit 9ecf359. The fix blocks http://, https:// and //, but can be bypassed using backslashes (\) - the endpoint still issues a server-side fetch.
PoC
References
- WEB https://github.com/withastro/astro/security/advisories/GHSA-qcpr-679q-rhm2
- ADVISORY https://nvd.nist.gov/vuln/detail/CVE-2025-59837
- WEB https://github.com/withastro/astro/commit/1e2499e8ea83ebfa233a18a7499e1ccf169e56f4
- WEB https://github.com/withastro/astro/commit/9ecf3598e2b29dd74614328fde3047ea90e67252
- PACKAGE https://github.com/withastro/astro
Ready to move
Start Securing
Free, no credit card | First findings in minutes