Vulnerabilities/

Astro is vulnerable to SSRF due to missing allowlist enforcement in remote image inferSize

Severity:
Medium

Description

A bug in Astro’s image pipeline allows bypassing image.domains / image.remotePatterns restrictions, enabling the server to fetch content from unauthorized remote hosts.

Recommendation

Update the @astrojs/node package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
@astrojs/node
Anything's wrong? Let us know Last updated on February 27, 2026