CVE-2025-55207 is an Open Redirect vulnerability affecting Astro, a web framework, in versions prior to 9.4.1, specifically when using the Node deployment adapter in standalone mode with trailingSlash set to "always". This allows attackers to craft malicious links that appear legitimate, potentially leading to credential theft or malware distribution. With a CVSS score of 5.5 (Medium), the attack requires no privileges or user interaction, but the impact is limited to low integrity and confidentiality. There is currently no evidence of active exploitation, public exploit code, or significant community discussion surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Withastro | Astro | < 9.4.1CNA affected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.