CVE-2025-64764

HIGH EXPLOITED NUCLEI

Astro < 5.15.8 - Basic XSS

Title source: rule

Description

Astro is a web framework. Prior to version 5.15.8, a reflected XSS vulnerability is present when the server islands feature is used in the targeted application, regardless of what was intended by the component template(s). This issue has been patched in version 5.15.8.

Nuclei Templates (1)

Astro - Reflected XSS via server islands feature
HIGHVERIFIEDby DhiyaneshDk,zhero___
Shodan: html:"_server-islands"

Scores

CVSS v3 7.1
EPSS 0.0029
EPSS Percentile 52.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:H/A:N

Details

VulnCheck KEV 2025-12-15
CWE
CWE-80
Status published
Products (2)
astro/astro < 5.15.8
npm/astro 0 - 5.15.8npm
Published Nov 19, 2025
Tracked Since Feb 18, 2026