{"id":"GHSA-x2rg-q646-7m2v","summary":"Koajs vulnerable to Cross-Site Scripting (XSS) at ctx.redirect() function","details":"### Summary\nIn koa \u003c 2.16.1 and \u003c 3.0.0-alpha.5, passing untrusted user input to ctx.redirect() even after sanitizing it, may execute javascript code on the user who use the app.\n\n### Patches\nThis issue is patched in  2.16.1 and 3.0.0-alpha.5.\n\n### PoC\nComing soon...\n\n### Impact\n1. Redirect user to another phishing site\n2. Make request to another endpoint of the application based on user's cookie\n3. Steal user's cookie","aliases":["CVE-2025-32379"],"modified":"2025-04-09T20:29:43Z","published":"2025-04-09T13:00:07Z","database_specific":{"github_reviewed_at":"2025-04-09T13:00:07Z","nvd_published_at":"2025-04-09T16:15:25Z","cwe_ids":["CWE-79"],"severity":"MODERATE","github_reviewed":true},"references":[{"type":"WEB","url":"https://github.com/koajs/koa/security/advisories/GHSA-x2rg-q646-7m2v"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-32379"},{"type":"WEB","url":"https://github.com/koajs/koa/commit/ff25eb4a7f2392df46481fe86355161067687312"},{"type":"PACKAGE","url":"https://github.com/koajs/koa"}],"affected":[{"package":{"name":"koa","ecosystem":"npm","purl":"pkg:npm/koa"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"2.16.1"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/04/GHSA-x2rg-q646-7m2v/GHSA-x2rg-q646-7m2v.json"}},{"package":{"name":"koa","ecosystem":"npm","purl":"pkg:npm/koa"},"ranges":[{"type":"SEMVER","events":[{"introduced":"3.0.0-alpha.1"},{"fixed":"3.0.0-alpha.5"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/04/GHSA-x2rg-q646-7m2v/GHSA-x2rg-q646-7m2v.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:L"}]}