KoaJS Koa HTTP Header response.js back redirect

CVE Details

Basic Information

Title KoaJS Koa HTTP Header response.js back redirect
Type cve
Published 2025-07-25T04:02:05.418Z
Modified 2025-07-25T04:02:05.418Z

Product Information

Vendor KoaJS
Product Koa
Version 3.0

CVSS Information

Base Score 5.1 (MEDIUM)
Attack Vector CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P

AI Analysis

AI Description An open redirect vulnerability in KoaJS Koa up to version 3.0.0 allows remote attackers to redirect users by manipulating the Referrer header. This could lead to phishing attacks or unauthorized access.
AI Severity Medium
AI Vendor KoaJS
AI Product Koa
AI Version 3.0.0

Affected Products

  • KoaJS Koa 3.0

Additional Information

CWE List CWE-601
Source VulDB

Description

A vulnerability, which was classified as problematic, was found in KoaJS Koa up to 3.0.0. Affected is the function back in the library lib/response.js of the component HTTP Header Handler. The manipulation of the argument Referrer leads to open redirect. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.