Junglewise Threat Intelligence

CVE-2025-55207: Astro Node adapter open redirect via trailing slash handling

CVE-2025-55207 · Severity: medium · CVSS 4 · Published 2025-08-15

Technologies: @astrojs/node (npm). Vendors: Astro, npm.

Executive brief

The Astro Node deployment adapter is vulnerable to open redirect attacks when configured with trailingSlash set to "always". An attacker can craft a malicious link with a double slash (e.g., //astro.build/press) that tricks the vulnerable server into redirecting users to an external website, enabling phishing, credential theft, or malware distribution attacks. No authentication is required to exploit this vulnerability.

Technical details

This is an open redirect vulnerability (CWE-601) in the @astrojs/node adapter's trailing slash normalization logic. When the adapter is configured in standalone mode with trailingSlash set to "always", URLs with protocol-relative paths (double slashes, e.g., //example.com/path) are not properly sanitized before being used in redirect responses. An unauthenticated attacker can exploit this via network access by crafting a specially formatted URL (https://victim.com//attacker.com/path) that the server incorrectly normalizes and redirects to the attacker's domain. The vulnerability affects @astrojs/node versions up to 9.4.0 and is fixed in version 9.4.1.

Affected products

  • Astro Node adapter <= 9.4.0

Timeline

  • 2025-08-15: disclosed
  • 2025-08-15: patched: Fixed in @astrojs/node 9.4.1

References

Related threats