Vulnerabilities/

Astro allows unauthorized third-party images in _image endpoint

Severity:
Medium

Description

In affected versions of astro, the image optimization endpoint in projects deployed with on-demand rendering allows images from unauthorized third-party domains to be served.

Recommendation

Update the astro package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
astro
Anything's wrong? Let us know Last updated on August 19, 2025

This issue is available in SmartScanner Professional

See Pricing