CVE 4.3 MEDIUM

Koa Vulnerable to Open Redirect via Trailing Double-Slash (//) in back Redirect Logic_CVE-2025-62595

4.3 / 10
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N

Description

Koa is expressive middleware for Node.js using ES2017 async functions. In versions 2.16.2 to before 2.16.3 and 3.0.1 to before 3.0.3, a bypass to CVE-2025-8129 was discovered in the Koa.js framework affecting its back redirect functionality. In certain circumstances, an attacker can manipulate the Referer header to force a user’s browser to navigate to an external, potentially malicious website. This occurs because the implementation incorrectly treats some specially crafted URLs as safe relative paths. Exploiting this vulnerability could allow attackers to perform phishing, social engineering, or other redirect-based attacks on users of affected applications. This issue has been patched in version 3.0.3.

Basic Information

ID CVE-2025-62595
Source GitHub_M
Published Oct 21, 2025 at 16:20
Modified Oct 21, 2025 at 16:35

Affected Product

Vendor koajs
Product koa
Version >= 2.16.2, < 2.16.3
Affected Versions koajs koa >= 2.16.2, < 2.16.3
koajs koa >= 3.0.1, < 3.0.3

CWE Classification

References

πŸ’­ Join the Security Discussion

πŸ”’ Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.