CVEFinder.io

CVE-2025-64757

â„šī¸ low
🔍 Scan for this CVE
Summary

Astro is a web framework. Prior to version 5.14.3, a vulnerability has been identified in the Astro framework's development server that allows arbitrary local file read access through the image optimization endpoint. The vulnerability affects Astro development environments and allows remote attackers to read any image file accessible to the Node.js process on the host system. This issue has been patched in version 5.14.3.

CVSS Score
3.5
Low
EPSS Score
0.0
Exploit Probability
Published Date
2025-11-19
First Seen: 2026-01-05
📊 Relative Risk Intelligence

This CVE is Lower Risk - more severe than 3.9% of all 329,456 vulnerabilities in our database.

#316,686
Below average severity
Severity Percentile
đŸŽ¯ CISA SSVC Assessment Updated: Nov 19, 2025
🔍 Exploitation Status
Poc
Proof-of-concept available
âš™ī¸ Automatable
NO
Requires human interaction
đŸ’Ĩ Technical Impact
Partial
Limited system impact
SSVC data provided by CISA
Last Modified 2025-11-20
CVSS Vector 3.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
CWE IDs (Weakness Types)

đŸ“Ļ Affected Products 1

🔗 References 2

🔗 Related CVEs 6

CVE ID Severity CVSS EPSS Summary Published
CVE-2026-50146 âš ī¸ high 7.1 0.2 Astro is a web framework. Prior to 6.3.3, when a component uses a client:* directive, Astro inserts named slot content i... 2026-06-22
CVE-2026-54298 đŸ”ļ medium 4.2 0.2 Astro is a web framework. Prior to 6.4.6, the spreadAttributes function in Astro's server-side rendering pipeline iterat... 2026-06-22
CVE-2026-54299 âš ī¸ high 7.5 0.2 Astro is a web framework. Prior to 6.4.6, Astro SSR apps with prerendered error pages (/404 or /500 using export const p... 2026-06-22
CVE-2026-45028 đŸ”ļ medium 6.1 0.0 Astro is a web framework. Astro versions prior to 6.1.10 used AES-GCM encryption to protect the confidentiality and inte... 2026-05-13
CVE-2026-41067 đŸ”ļ medium 6.1 0.0 Astro is a web framework. Prior to 6.1.6, the defineScriptVars function in Astro's server-side rendering pipeline uses a... 2026-04-24
CVE-2026-33769 đŸ”ļ medium 5.3 0.0 Astro is a web framework. From version 2.10.10 to before version 5.18.1, this issue concerns Astro's remotePatterns path... 2026-03-24
These CVEs affect the same products