Vulnerable Library - starlight-0.37.7.tgz
Path to dependency file: /tutorials/video-javascript-client-observability/package.json
Path to vulnerable library: /sources/video-javascript-client-observability/package.json,/tutorials/video-node-client-observability/package.json,/tutorials/video-javascript-client-observability/package.json,/sources/video-node-client-observability/package.json
Found in HEAD commit: f400f39c07df86338418f7902a27a7c22c1442b4
Vulnerabilities
| Vulnerability |
Severity |
CVSS |
Dependency |
Type |
Fixed in (starlight version) |
Remediation Possible** |
| CVE-2025-65019 |
Medium |
5.4 |
internal-helpers-0.6.1.tgz |
Transitive |
0.38.0 |
✅ |
**In some cases, Remediation PR cannot be created automatically for a vulnerability despite the availability of remediation
Details
CVE-2025-65019
Vulnerable Library - internal-helpers-0.6.1.tgz
Internal helpers used by core Astro packages.
Library home page: https://registry.npmjs.org/@astrojs/internal-helpers/-/internal-helpers-0.6.1.tgz
Path to dependency file: /sources/video-javascript-client-observability/package.json
Path to vulnerable library: /sources/video-javascript-client-observability/package.json,/tutorials/video-node-client-observability/package.json,/tutorials/video-javascript-client-observability/package.json,/sources/video-node-client-observability/package.json
Dependency Hierarchy:
- starlight-0.37.7.tgz (Root Library)
- mdx-4.2.6.tgz
- markdown-remark-6.3.1.tgz
- ❌ internal-helpers-0.6.1.tgz (Vulnerable Library)
Found in HEAD commit: f400f39c07df86338418f7902a27a7c22c1442b4
Found in base branch: main
Vulnerability Details
Astro is a web framework. Prior to version 5.15.9, when using Astro's Cloudflare adapter (@astrojs/cloudflare) with output: 'server', the image optimization endpoint (/_image) contains a critical vulnerability in the isRemoteAllowed() function that unconditionally allows data: protocol URLs. This enables Cross-Site Scripting (XSS) attacks through malicious SVG payloads, bypassing domain restrictions and Content Security Policy protections. This issue has been patched in version 5.15.9.
Publish Date: 2025-11-19
URL: CVE-2025-65019
CVSS 3 Score Details (5.4)
Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Network
- Attack Complexity: Low
- Privileges Required: None
- User Interaction: Required
- Scope: Unchanged
- Impact Metrics:
- Confidentiality Impact: Low
- Integrity Impact: Low
- Availability Impact: None
For more information on CVSS3 Scores, click here.
Suggested Fix
Type: Upgrade version
Release Date: 2025-11-19
Fix Resolution (@astrojs/internal-helpers): 0.7.5
Direct dependency fix Resolution (@astrojs/starlight): 0.38.0
⛑️ Automatic Remediation will be attempted for this issue.
⛑️Automatic Remediation will be attempted for this issue.
Path to dependency file: /tutorials/video-javascript-client-observability/package.json
Path to vulnerable library: /sources/video-javascript-client-observability/package.json,/tutorials/video-node-client-observability/package.json,/tutorials/video-javascript-client-observability/package.json,/sources/video-node-client-observability/package.json
Found in HEAD commit: f400f39c07df86338418f7902a27a7c22c1442b4
Vulnerabilities
**In some cases, Remediation PR cannot be created automatically for a vulnerability despite the availability of remediation
Details
Vulnerable Library - internal-helpers-0.6.1.tgz
Internal helpers used by core Astro packages.
Library home page: https://registry.npmjs.org/@astrojs/internal-helpers/-/internal-helpers-0.6.1.tgz
Path to dependency file: /sources/video-javascript-client-observability/package.json
Path to vulnerable library: /sources/video-javascript-client-observability/package.json,/tutorials/video-node-client-observability/package.json,/tutorials/video-javascript-client-observability/package.json,/sources/video-node-client-observability/package.json
Dependency Hierarchy:
Found in HEAD commit: f400f39c07df86338418f7902a27a7c22c1442b4
Found in base branch: main
Vulnerability Details
Astro is a web framework. Prior to version 5.15.9, when using Astro's Cloudflare adapter (@astrojs/cloudflare) with output: 'server', the image optimization endpoint (/_image) contains a critical vulnerability in the isRemoteAllowed() function that unconditionally allows data: protocol URLs. This enables Cross-Site Scripting (XSS) attacks through malicious SVG payloads, bypassing domain restrictions and Content Security Policy protections. This issue has been patched in version 5.15.9.
Publish Date: 2025-11-19
URL: CVE-2025-65019
CVSS 3 Score Details (5.4)
Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Network
- Attack Complexity: Low
- Privileges Required: None
- User Interaction: Required
- Scope: Unchanged
- Impact Metrics:
- Confidentiality Impact: Low
- Integrity Impact: Low
- Availability Impact: None
For more information on CVSS3 Scores, click here.Suggested Fix
Type: Upgrade version
Release Date: 2025-11-19
Fix Resolution (@astrojs/internal-helpers): 0.7.5
Direct dependency fix Resolution (@astrojs/starlight): 0.38.0
⛑️ Automatic Remediation will be attempted for this issue.
⛑️Automatic Remediation will be attempted for this issue.