← Back

CVE-2025-64764

Published: Nov 19, 2025Modified: Jun 17, 2026

JSON object

Loading...
5.4
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
Exploitability: 2.8 / Impact: 2.5
Source: NVD

Description

Astro is a web framework. Prior to version 5.15.8, a reflected XSS vulnerability is present when the server islands feature is used in the targeted application, regardless of what was intended by the component template(s). This issue has been patched in version 5.15.8.

Affected (1)

Products: Astro: Astro
1 product
Astro
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Before 5.15.8

References (2)

Timeline

No history available yet.