Executive brief
Astro's image optimization endpoint, used by websites to serve resized and optimized images, has a flaw that allows attackers to serve images from unauthorized external domains. By using a specially crafted URL, an attacker can bypass the site owner's domain restrictions and serve any third-party image through the site's domain. This could enable cross-site scripting attacks if malicious SVG images are served, potentially compromising visitor accounts or data.
Technical details
The vulnerability is a domain validation bypass in Astro's /_image endpoint (CWE-79). The endpoint is designed to restrict image optimization to local images and developer-authorized remote domains (configured via image.domains or image.remotePatterns), but fails to properly parse protocol-relative URLs (e.g., //example.com/image.png). An unauthenticated attacker on the network can bypass these restrictions by crafting a request like /_image?href=//unauthorized-domain.com/image.png, causing the server to fetch and serve the unauthorized image. This is particularly dangerous for SVG images, which could contain embedded JavaScript leading to XSS. The fix is available in Astro 5.13.2, 4.16.19, and @astrojs/node 9.1.1 or later.
Affected products
- Astro Astro 5.0.0-alpha.0 to 5.13.1, all versions up to 4.16.18
- Astro @astrojs/node all versions up to 9.1.0
Timeline
- 2025-08-19: disclosed: Security advisory published
- 2025-08-19: patched: Fixes available: Astro 5.13.2, 4.16.19, @astrojs/node 9.1.1