CVE-2025-64764
HIGH EXPLOITED NUCLEIAstro < 5.15.8 - Basic XSS
Title source: ruleDescription
Astro is a web framework. Prior to version 5.15.8, a reflected XSS vulnerability is present when the server islands feature is used in the targeted application, regardless of what was intended by the component template(s). This issue has been patched in version 5.15.8.
Nuclei Templates (1)
Astro - Reflected XSS via server islands feature
HIGHVERIFIEDby DhiyaneshDk,zhero___
Shodan:
html:"_server-islands"
Scores
CVSS v3
7.1
EPSS
0.0029
EPSS Percentile
52.0%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:H/A:N
Details
VulnCheck KEV
2025-12-15
CWE
CWE-80
Status
published
Products (2)
astro/astro
< 5.15.8
npm/astro
0 - 5.15.8npm
Published
Nov 19, 2025
Tracked Since
Feb 18, 2026