Astro SSR - Open Redirect
CVE-2025-54793
Verified
Description
Astro 5.2.0 through 5.12.7 contains an open redirect caused by improper handling of paths with double slashes in trailing slash redirection logic, letting attackers redirect users to arbitrary external domains, exploit requires on-demand SSR with Node or Cloudflare adapters.
Severity
Medium
CVSS Score
6.1
Exploit Probability
1%
Affected Product
astro
Published Date
March 24, 2026
Template Author
dhiyaneshdk
CVE-2025-54793.yaml
6.1Score
CVSS Metrics
CVSS Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CVE ID:
cve-2025-54793
CWE ID:
cwe-601
Remediation Steps
Upgrade to version 5.12.8 or later; alternatively, block outgoing redirects with Location headers starting with // at the network level.