Astro 5.2.0 through 5.12.7 contains an open redirect caused by improper handling of paths with double slashes in trailing slash redirection logic, letting attackers redirect users to arbitrary external domains, exploit requires on-demand SSR with Node or Cloudflare adapters.
id: CVE-2025-54793
info:
name: Astro SSR - Open Redirect
author: DhiyaneshDk
severity: medium
...