Matthew Phillips
10 exploits
Active since Oct 2024
Astro: Server island encrypted parameters vulnerable to cross-component replay
CVSS 6.1
Astro 5.13.4-5.13.9 - Server-Side Request Forgery via Backslash Bypass in Image Proxy
CVSS 7.2
Astro 2.16.0-5.15.4 - Server-Side Request Forgery via x-forwarded-proto Header
CVSS 6.5
Astro: Unauthenticated Path Override via `x-astro-path` / `x_astro_path`
CVSS 6.5
Astro 9.0.0 to 9.5.3 - inferSize Image Pipeline Server-Side Request Forgery
CVSS 6.5
@astrojs/node < 9.5.4 - Server-Side Request Forgery via Host Header Manipulation
CVSS 8.6
@astrojs/node 9.0.0-9.5.3 - Unauthenticated Denial of Service via Oversized Server Action Request
CVSS 5.9
Astro 3.0.0-4.16.0 - Cross-Site Scripting via DOM Clobbering in Client-Side Router
CVSS 5.9
Astro < 5.15.8 - Path Traversal via Decoded URI Bypass
CVSS 5.3
Astro < 5.15.8 - Unauthenticated Authorization Bypass via Double URL Encoding
CVSS 6.5