CVE-2025-8129

LOW

Koa < 2.16.2 - Open Redirect

Title source: rule
STIX 2.1

Description

A vulnerability, which was classified as problematic, was found in KoaJS Koa up to 3.0.0. Affected is the function back in the library lib/response.js of the component HTTP Header Handler. The manipulation of the argument Referrer leads to open redirect. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

Scores

CVSS v3 3.5
EPSS 0.0008
EPSS Percentile 24.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-601
Status published
Products (3)
koajs/koa 3.0.0 (7 CPE variants)
koajs/koa 2.0.0 - 2.16.2
npm/koa 2.0.0 - 2.16.2npm
Published Jul 25, 2025
Tracked Since Feb 18, 2026