Description
A vulnerability has been identified in the Astro framework’s development server that allows arbitrary local file read access through the image optimization endpoint. The vulnerability affects Astro development environments and allows remote attackers to read any image file accessible to the Node.js process on the host system.
Recommendation
Update the astro package to the latest compatible version. Followings are version details:
- Affected version(s): < 5.14.3
- Patched version(s): 5.14.3
References
Related Issues
- Gatsby develop server has Local File Inclusion vulnerability - CVE-2023-34238
- jsPDF has Local File Inclusion/Path Traversal vulnerability - CVE-2025-68428
- Websites were able to send any requests to the development server and read the response in vite - CVE-2025-24010
- Astro development server error page is vulnerable to reflected Cross-site Scripting - CVE-2025-64745
- Tags:
- npm
- astro
Anything's wrong? Let us know Last updated on November 19, 2025