4.3
/ 10
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
Description
Koa is expressive middleware for Node.js using ES2017 async functions. In versions 2.16.2 to before 2.16.3 and 3.0.1 to before 3.0.3, a bypass to CVE-2025-8129 was discovered in the Koa.js framework affecting its back redirect functionality. In certain circumstances, an attacker can manipulate the Referer header to force a userβs browser to navigate to an external, potentially malicious website. This occurs because the implementation incorrectly treats some specially crafted URLs as safe relative paths. Exploiting this vulnerability could allow attackers to perform phishing, social engineering, or other redirect-based attacks on users of affected applications. This issue has been patched in version 3.0.3.
Basic Information
ID
CVE-2025-62595
Source
GitHub_M
Published
Oct 21, 2025 at 16:20
Modified
Oct 21, 2025 at 16:35
Affected Product
Vendor
koajs
Product
koa
Version
>= 2.16.2, < 2.16.3
Affected Versions
koajs koa >= 2.16.2, < 2.16.3
koajs koa >= 3.0.1, < 3.0.3
koajs koa >= 3.0.1, < 3.0.3