Astro is a modern site builder with web best practices, performance, and DX front-of-mind.
82%
Total Score
61
50
100
100
100
| Title | Versions | Severity |
|---|---|---|
CVE-2025-66202 astro is vulnerable to Use of Non-Canonical URL Paths for Authorization Decisions in versions 0.0.0 - 5.15.8. | 0.0.0 - 5.15.8 | Medium |
AIKIDO-2025-10879 Pre-CVE Found by Aikido Intel before public disclosure or CVE publication. astro is vulnerable to Authentication Bypass Using an Alternate Path or Channel in versions 3.5.6 - 5.16.2. | 3.5.6 - 5.16.2 | High |
AIKIDO-2025-10825 astro is vulnerable to Cross Site Scripting (XSS) in versions 4.12.0 - 5.15.7. | 4.12.0 - 5.15.7 | Low |
CVE-2025-65019 astro is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in versions 0.0.0 - 5.15.9. | 0.0.0 - 5.15.9 | Medium |
CVE-2025-64765 astro is vulnerable to Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in versions 0.0.0 - 5.15.8. | 0.0.0 - 5.15.8 | Medium |
| Dependency | Last Release | Score |
|---|---|---|
dlv Version ^1.1.3 | — | — |
zod Version ^3.25.76 | — | — |
clsx Version ^2.1.1 | — | — |
diff Version ^8.0.3 | — | — |
dset Version ^3.1.4 | — | — |
Secure your code, cloud, and runtime environments in one central system. Find and fix vulnerabilities automatically.
No credit card required | Scan results in 32secs.
SOC 2Compliant
ISO 27001Compliant