Junglewise Threat Intelligence

CVE-2025-64764: Astro reflected XSS via server islands feature

CVE-2025-64764 · Severity: low · CVSS 3.1 · Published 2025-11-19

Technologies: astro (npm). Vendors: npm, Astro.

Executive brief

Astro is a web framework used to build fast, content-focused websites. The server islands feature allows dynamic server-rendered components, but contains an XSS vulnerability that allows attackers to inject malicious scripts through URL parameters. An attacker can craft a special URL that, when clicked by a user, executes arbitrary JavaScript in the victim's browser, potentially stealing session cookies, credentials, or performing actions on behalf of the user.

Technical details

The vulnerability is a reflected cross-site scripting (XSS) flaw in Astro's server islands feature. The `/_server-islands/[name]` endpoint accepts three parameters: `e` (component export), `p` (properties), and `s` (slots). When the `e` parameter is set to "file", the endpoint generates an HTML template using the island's absolute file path as an HTML tag name and injects the `s` parameter value directly as child content using `markHTMLString` without proper sanitization. This allows an unauthenticated attacker to inject arbitrary HTML/JavaScript via the `s` parameter in a URL. The attack requires user interaction (clicking a malicious link) but works regardless of the actual component template design. The vulnerability affects all versions up to 5.15.6 and is patched in version 5.15.8.

Affected products

  • Astro Astro <= 5.15.6

Timeline

  • 2025-11-19: disclosed
  • 2025-11-19: patched: Fixed in version 5.15.8

References

Related threats