CVE-2025-61925 describes an unvalidated reflection of the X-Forwarded-Host header in Astro, a web framework, prior to version 5.14.2. This vulnerability allows an attacker to manipulate the Astro.url value by sending a malicious X-Forwarded-Host header, potentially leading to canonical link manipulation, redirection of login credentials, or persistent malicious content in caching proxies. The CVSS score is 6.5 (Medium), indicating a network-based attack with low complexity, resulting in potential low integrity and availability impacts. There is currently no evidence of active exploitation, public exploit code, or significant community discussion surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 5.14.2CPE matchmatch criteria | cpe:2.3:a:astro:astro:*:*:*:*:*:node.js:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
URL manipulation via unsanitized headers leads to path-based middleware protections bypass and potential SSRF/cache-poisoning + CVE-2025-61925 bypass
Nov 13, 2025URL manipulation via unsanitized headers leads to path-based middleware protections bypass and potential SSRF/cache-poisoning + CVE-2025-61925 bypass
Nov 13, 2025URL manipulation via unsanitized headers leads to path-based middleware protections bypass and potential SSRF/cache-poisoning + CVE-2025-61925 bypass
Nov 13, 2025Astro's `X-Forwarded-Host` is reflected without validation
Oct 10, 2025