CVE-2025-8129

LOW

KoaJS Koa 2.0.0-2.16.2 - Open Redirect via Referrer Header

Title source: llm
STIX 2.1

Description

A vulnerability, which was classified as problematic, was found in KoaJS Koa up to 3.0.0. Affected is the function back in the library lib/response.js of the component HTTP Header Handler. The manipulation of the argument Referrer leads to open redirect. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

References (5)

Core 5
Core References
Third Party Advisory, VDB Entry vdb-entry technical-description
https://vuldb.com/?id.317514
Permissions Required, VDB Entry signature permissions-required
https://vuldb.com/?ctiid.317514
Third Party Advisory, VDB Entry third-party-advisory
https://vuldb.com/?submit.619741
Exploit, Issue Tracking, Patch, Vendor Advisory issue-tracking
https://github.com/koajs/koa/issues/1892
Exploit, Issue Tracking, Patch, Third Party Advisory, Vendor Advisory exploit issue-tracking
https://github.com/koajs/koa/issues/1892#issue-3213028583

Scores

CVSS v3 3.5
EPSS 0.0022
EPSS Percentile 12.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-601
Status published
Products (3)
koajs/koa 3.0.0 (7 CPE variants)
koajs/koa 2.0.0 - 2.16.2
npm/koa 2.0.0 - 2.16.2npm
Published Jul 25, 2025
Tracked Since Feb 18, 2026