Junglewise Threat Intelligence

CVE-2025-65019: Astro Cloudflare adapter stored XSS in /_image endpoint

CVE-2025-65019 · Severity: low · CVSS 3.1 · Published 2025-11-19

Technologies: astro (npm). Vendors: Astro, npm.

Executive brief

Astro's Cloudflare adapter contains a cross-site scripting vulnerability in its image optimization endpoint. When processing image requests, the endpoint redirects to data: URLs without properly sanitizing them, allowing attackers to embed and execute malicious JavaScript in SVG images. This could lead to session hijacking, account takeover, or theft of sensitive data from site visitors.

Technical details

The vulnerability is a stored/reflected cross-site scripting (XSS) flaw in the /_image endpoint of the Astro Cloudflare adapter when running with output: 'server'. The root cause lies in the isRemoteAllowed() function, which unconditionally allows data: URLs without validation. When an attacker crafts a request with a data: URL parameter pointing to a malicious SVG containing JavaScript, the Cloudflare adapter performs a 302 redirect directly to the data: URL, causing the browser to render and execute the embedded script. This bypasses typical security controls like image.domains configuration and Content-Security-Policy. The vulnerability affects Astro versions before 5.15.9 and @astrojs/cloudflare versions up to 12.6.10. A patch is available in Astro 5.15.9.

Affected products

  • Astro Astro < 5.15.9 when using @astrojs/cloudflare adapter with output: 'server'
  • Astro @astrojs/cloudflare ≤ 12.6.10

Timeline

  • 2025-11-19: disclosed: Vulnerability disclosed via GHSA-fvmw-cj7j-j39q
  • 2025-11-19: patched: Fixed in Astro 5.15.9

References

Related threats