CVE-2025-54793 is an open redirect vulnerability in Astro, a web framework for content-driven websites. Affected versions are 5.2.0 through 5.12.7. The flaw exists in the trailing-slash redirection logic when handling request paths containing double slashes. By supplying a crafted path such as https://mydomain.com//malicious-site.com/, an attacker can cause the application to emit a redirect with a protocol-relative Location header value beginning with //, which browsers interpret as a redirect to an external domain. The issue affects Astro deployments using on-demand rendering (SSR) with the Node or Cloudflare adapters. Static sites and deployments to Netlify or Vercel are not affected. The vulnerability was fixed in Astro version 5.12.8.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Location header value starts with //, since protocol-relative redirects are the exploitation mechanism described. Additional defensive validation can include normalizing or rejecting request paths containing unexpected double slashes before redirect handling.Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository contains a single file, index.html, implementing a standalone browser-based proof of concept rather than a traditional memory-corruption or remote-code-execution exploit. The page is a styled fake Anduril Lattice login interface intended to demonstrate the impact of CVE-2025-54793, described in the code as an open redirect affecting armory.anduril.com. When a user submits the form, client-side JavaScript intercepts the submission, shows a loading spinner, then captures the entered username and password. The credentials are logged to the browser console, stored in localStorage as 'poc_credentials', and displayed in an alert dialog. No exfiltration to a remote server is present in the provided code, so this is best characterized as a phishing/credential-capture PoC demonstrating how an open redirect could be abused to impersonate a trusted login page. Repository structure is minimal: one HTML file containing embedded CSS for branding/UI and embedded JavaScript for form handling and credential capture.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.