CVE-2025-55303 | withastro up to 4.16.17/5.13.1 Image Optimization Endpoint /_image cross site scripting (GHSA-xf8x-j4p2-f749)
A vulnerability was found in withastro astro up to 4.16.17/5.13.1. It has been declared as problematic. This impacts an unknown function of the file /_image of the component Image Optimization Endpoint. Such manipulation leads to cross site scripting.
This vulnerability is listed as CVE-2025-55303. The attack may be performed from a remote location. There is no available exploit.
It is recommended to upgrade the affected component.