Astro < 5.13.2 and < 4.16.18 contains an information disclosure vulnerability caused by improper validation of protocol-relative URLs in the image optimization endpoint, letting attackers serve images from unauthorized third-party domains, exploit requires on-demand rendering deployment.
id: CVE-2025-55303
info:
name: Astro - Unauthorized Third-Party Image Access
author: theamanraw
...