/Vulnerability Library

Astro SSR - Open Redirect

CVE-2025-54793
Verified

Description

Astro 5.2.0 through 5.12.7 contains an open redirect caused by improper handling of paths with double slashes in trailing slash redirection logic, letting attackers redirect users to arbitrary external domains, exploit requires on-demand SSR with Node or Cloudflare adapters.

Severity

Medium

CVSS Score

6.1

Exploit Probability

1%

Affected Product

astro

Published Date

March 24, 2026

Template Author

dhiyaneshdk

CVE-2025-54793.yaml
6.1Score

CVSS Metrics

CVSS Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CVE ID:
cve-2025-54793
CWE ID:
cwe-601

References

https://github.com/withastro/astro/security/advisories/GHSA-cq8c-xv66-36gwhttps://nvd.nist.gov/vuln/detail/CVE-2025-54793https://github.com/withastro/astro/commit/9ec88a04f93611cc07deff76ef6a18c88d6a77b9

Remediation Steps

Upgrade to version 5.12.8 or later; alternatively, block outgoing redirects with Location headers starting with // at the network level.