References https://github.com/withastro/astro/security/advisories/GHSA-wrwg-2hg8-v723 https://nvd.nist.gov/vuln/detail/CVE-2025-64764 https://access.redhat.com/security/cve/cve-2025-64764 https://www.thesmartscanner.com/vulnerability-list/astro-vulnerable-to-reflected-xss-via-the-server-islands-feature https://cve.imfht.com/detail/CVE-2025-64764?lang=en https://security.snyk.io/vuln/SNYK-JS-ASTRO-14059122 https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2025/CVE-2025-64764.yaml https://guide.sonatype.com/vulnerability/CVE-2025-64764 https://vulert.com/vuln-db/CVE-2025-64764 https://pentest-tools.com/vulnerabilities-exploits/astro-reflected-xss-via-server-islands-feature_28182
Related VulnerabilitiesPoCCVE-2026-25545: Astro SSR - Server-Side Request ForgeryPoCCVE-2025-54793: Astro SSR - Open RedirectPoCCVE-2025-55303: Astro - Unauthorized Third-Party Image AccessPoCCVE-2024-56159: Astro - Information DisclosureCodeastro Real_estate_management_system注入漏洞(CVE-2025-14899)Codeastro Real_estate_management_system注入漏洞(CVE-2025-14897)Astro Web Framework Cloudflare /_image 服务器端请求伪造漏洞(CVE-2025-58179)PoCCVE-2025-64525: Astro - Broken Access ControlPoCCVE-2025-64764: Astro - Reflected XSS via server islands featureCodeAstro Gym Management System SQL注入漏洞CodeAstro Online Leave Application SQL注入漏洞