MEDIUM🇵🇱 Wersja polska

CVE-2025-62595

CVSS 4.3v3.1pub. 2025-10-21upd. 2026-01-20

Koa is expressive middleware for Node.js using ES2017 async functions. In versions 2.16.2 to before 2.16.3 and 3.0.1 to before 3.0.3, a bypass to CVE-2025-8129 was discovered in the Koa.js framework affecting its back redirect functionality. In certain circumstances, an attacker can manipulate the Referer header to force a user’s browser to navigate to an external, potentially malicious website. This occurs because the implementation incorrectly treats some specially crafted URLs as safe relative paths. Exploiting this vulnerability could allow attackers to perform phishing, social engineering, or other redirect-based attacks on users of affected applications. This issue has been patched in version 3.0.3.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
  • Koajs Koa

    APP
    Koajs
    2.16.23.0.1 – 3.0.3 (excl.)
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2025-25200CRITICAL9.2PL ✓same product

Atak DoS przez podatność ReDoS w nagłówkach HTTP w Koa (Node.js)

CVE-2026-27959HIGH7.5same product

Koa is middleware for Node.js using ES2017 async functions. Prior to versions 3.1.2 and 2.16.4, Koa's `ctx.hos...

CVE-2025-32379MEDIUM5.0same product

Koa is expressive middleware for Node.js using ES2017 async functions. In koa < 2.16.1 and < 3.0.0-alpha.5, pa...

CVE-2025-8129LOW2.0same product

Podatliwość w KoaJS Koa do wersji 3.0.0 została klasyfikowana jako problematyczna. Dotyczy funkcji back w plik...

CVE-2023-49803HIGH8.6same vendor

@koa/cors npm provides Cross-Origin Resource Sharing (CORS) for koa, a web framework for Node.js. Prior to ver...