VYPR
Medium severity5.0NVD Advisory· Published Apr 9, 2025· Updated Jun 17, 2026

CVE-2025-32379

CVE-2025-32379

Description

Koa is expressive middleware for Node.js using ES2017 async functions. In koa < 2.16.1 and < 3.0.0-alpha.5, passing untrusted user input to ctx.redirect() even after sanitizing it, may execute javascript code on the user who use the app. This issue is patched in 2.16.1 and 3.0.0-alpha.5.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
koanpm
< 2.16.12.16.1
koanpm
>= 3.0.0-alpha.1, < 3.0.0-alpha.53.0.0-alpha.5

Affected products

8
  • Koajs/Koa7 versions
    cpe:2.3:a:koajs:koa:*:*:*:*:*:node.js:*:*+ 6 more
    • cpe:2.3:a:koajs:koa:*:*:*:*:*:node.js:*:*range: <2.16.1
    • cpe:2.3:a:koajs:koa:3.0.0:alpha0:*:*:*:node.js:*:*
    • cpe:2.3:a:koajs:koa:3.0.0:alpha1:*:*:*:node.js:*:*
    • cpe:2.3:a:koajs:koa:3.0.0:alpha2:*:*:*:node.js:*:*
    • cpe:2.3:a:koajs:koa:3.0.0:alpha3:*:*:*:node.js:*:*
    • cpe:2.3:a:koajs:koa:3.0.0:alpha4:*:*:*:node.js:*:*
    • (no CPE)range: >= 3.0.0-alpha.0, < 3.0.0-alpha.5
  • ghsa-coords
    Range: < 2.16.1

Patches

Vulnerability mechanics

References

4

News mentions

0

No linked articles in our index yet.