Astro's bypass of image proxy domain validation leads to SSRF and potential XSS
This is a patch bypass of CVE-2025-58179 in commit 9ecf359. The fix blocks http://, https:// and //, but can be bypassed using backslashes () - the endpoint still issues a server-side fetch.