PT-2025-30726 · Koajs · Koajs

Zast.Ai

·

Published

2025-07-25

·

Updated

2026-01-20

·

CVE-2025-8129

CVSS v2.0

4.0

Medium

VectorAV:N/AC:L/Au:S/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Koa versions up to 3.0.0
Description A problematic issue exists in KoaJS Koa. The back function within the HTTP Header Handler component, located in lib/response.js, is susceptible to open redirect attacks through manipulation of the Referrer argument. This issue can be exploited remotely. The exploit has been publicly disclosed.
Recommendations Versions prior to 3.0.0 are affected. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Open Redirect

Weakness Enumeration

Related Identifiers

CVE-2025-8129
GHSA-JGMV-J7WW-JX2X
GHSA-MVW6-62QV-VMQF

Affected Products

Koajs