Description
A vulnerability has been identified in the Astro framework’s development server that allows arbitrary local file read access through the image optimization endpoint. The vulnerability affects Astro development environments and allows remote attackers to read any image file accessible to the Node.js process on the host system.
Recommendation
Update the astro package to the latest compatible version. Followings are version details:
- Affected version(s): < 5.14.3
- Patched version(s): 5.14.3
References
Related Issues
- Astro development server error page is vulnerable to reflected Cross-site Scripting - CVE-2025-64745
- Vite Vulnerable to Arbitrary File Read via Vite Dev Server WebSocket - CVE-2026-39363
- Websites were able to send any requests to the development server and read the response in vite - CVE-2025-24010
- Gatsby develop server has Local File Inclusion vulnerability - CVE-2023-34238
You might also like:
- Tags:
- npm
- astro
Anything's wrong? Let us know Last updated on November 19, 2025


