Vulnerabilities/

Astros's duplicate trailing slash feature leads to an open redirection security issue

Severity:
Medium

Description

There is an Open Redirection vulnerability in the trailing slash redirection logic when handling paths with double slashes. This allows an attacker to redirect users to arbitrary external domains by crafting URLs such as https://mydomain.com//malicious-site.com/. This increases the risk of phishing and other social engineering attacks.

Recommendation

Update the astro package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
astro
Anything's wrong? Let us know Last updated on August 08, 2025

This issue is available in SmartScanner Professional

See Pricing