CVE-2025-32379
09.04.2025, 16:15
Koa is expressive middleware for Node.js using ES2017 async functions. In koa < 2.16.1 and < 3.0.0-alpha.5, passing untrusted user input to ctx.redirect() even after sanitizing it, may execute javascript code on the user who use the app. This issue is patched in 2.16.1 and 3.0.0-alpha.5.
| Vendor | Product | Version |
|---|---|---|
| koajs | koa | 𝑥 < 2.16.1 |
| koajs | koa | 3.0.0:alpha0 |
| koajs | koa | 3.0.0:alpha1 |
| koajs | koa | 3.0.0:alpha2 |
| koajs | koa | 3.0.0:alpha3 |
| koajs | koa | 3.0.0:alpha4 |
𝑥
= Vulnerable software versions