Security Advisories for @astrojs/netlify in npm
Low
11 days ago
@astrojs/netlify generates an overly-broad Netlify Image CDN allowlist because remotePatterns.pathname metacharacters are not escaped
npm
@astrojs/netlify
Moderate
about 2 months ago
@astrojs/netlify broadens Astro image.remotePatterns in Netlify Image CDN config
npm
@astrojs/netlify
Potential
High
9 months ago
Astro's bypass of image proxy domain validation leads to SSRF and potential XSS
npm
astro
Potential
Potential
High
11 months ago
Server-Side Request Forgery via /_image endpoint in Astro Cloudflare adapter
npm
@astrojs/cloudflare
Potential
Moderate
12 months ago
Astro allows unauthorized third-party images in _image endpoint
npm
astro, @astrojs/node
Potential
Moderate
12 months ago
@astrojs/node's trailing slash handling causes open redirect issue
npm
@astrojs/node
Potential
Moderate
12 months ago
Astros's duplicate trailing slash feature leads to an open redirection security issue
npm
astro
Potential
High
over 1 year ago
Astro's server source code is exposed to the public if sourcemaps are enabled
npm
astro
Potential
Potential
Moderate
almost 2 years ago
DOM Clobbering Gadget found in astro's client-side router that leads to XSS
npm
astro