Intel

AIKIDO-2025-10825

astro is vulnerable to Cross Site Scripting (XSS)

Cross Site Scripting (XSS)CVE-2025-64764 Published Nov 19, 2025

30

Low Risk

This Affects:

JSastro
4.12.0 - 5.15.7
Fixed in 5.15.8
Are you affected? Scan for Free

TL;DR

Affected versions of this package are vulnerable to cross-site scripting (XSS). The patched version strengthens the security of Server Islands slots by encrypting slot data before it is sent to the browser, aligning it with the security model already used for props. This ensures the integrity of slot content and prevents injection attacks, even when component templates do not explicitly support slots.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

astro is vulnerable to Cross Site Scripting (XSS) in versions 4.12.0 - 5.15.7.

How to fix this

Upgrade the astro library to the patch version.