{"id":"CVE-2025-66202","aliases":["GHSA-whqg-ppgf-wp8c"],"url":"https://o3.security/vulnerability/CVE-2025-66202","summary":"Astro has an Authentication Bypass via Double URL Encoding, a bypass for CVE-2025-64765","details":"Astro is a web framework. Versions 5.15.7 and below have a double URL encoding bypass which allows any unauthenticated attacker to bypass path-based authentication checks in Astro middleware, granting unauthorized access to protected routes. While the original CVE-2025-64765 was fixed in v5.15.8, the fix is insufficient as it only decodes once. By using double-encoded URLs, attackers can still bypass authentication and access any route protected by middleware pathname checks. This issue is fixed in version 5.15.8.","published":"2025-12-08T23:41:21.976Z","modified":"2026-08-08T03:48:15.995189440Z","cvss":{"score":6.5,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"npm","name":"astro","fixedVersion":"5.15.8"}],"fix":{"url":"https://github.com/withastro/astro/commit/6f800813516b07bbe12c666a92937525fddb58ce","label":"withastro/astro@6f80081"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/66xxx/CVE-2025-66202.json"},{"type":"ADVISORY","url":"https://github.com/withastro/astro/security/advisories/GHSA-ggxq-hp9w-j794"},{"type":"ADVISORY","url":"https://github.com/withastro/astro/security/advisories/GHSA-whqg-ppgf-wp8c"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-66202"},{"type":"FIX","url":"https://github.com/withastro/astro/commit/6f800813516b07bbe12c666a92937525fddb58ce"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-08T03:48:15.995189440Z"}}