Medium severity5.4GHSA Advisory· Published May 17, 2021· Updated Jun 17, 2026
CVE-2021-23384
CVE-2021-23384
Description
The package koa-remove-trailing-slashes before 2.0.2 are vulnerable to Open Redirect via the use of trailing double slashes in the URL when accessing the vulnerable endpoint (such as https://example.com//attacker.example/). The vulnerable code is in index.js::removeTrailingSlashes(), as the web server uses relative URLs instead of absolute URLs.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
koa-remove-trailing-slashesnpm | < 2.0.2 | 2.0.2 |
Affected products
3- Range: < 2.0.2
- cpe:2.3:a:koa-remove-trailing-slashes_project:koa-remove-trailing-slashes:*:*:*:*:*:node.js:*:*Range: <2.0.2
Patches
Vulnerability mechanics
References
4- snyk.io/vuln/SNYK-JS-KOAREMOVETRAILINGSLASHES-1085708nvdExploitThird Party AdvisoryWEB
- github.com/advisories/GHSA-r773-pmw3-f4mrghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2021-23384ghsaADVISORY
- github.com/vgno/koa-remove-trailing-slashes/commit/e7ce4000e9fe4d957332df1056640a22ebea28eeghsaWEB
News mentions
0No linked articles in our index yet.