Koa.js Framework Redirect Vulnerability in Node.js
CVE-2025-62595

4.3MEDIUM

Key Information:

Vendor

Koajs

Status
Vendor
CVE Published:
21 October 2025

What is CVE-2025-62595?

The Koa.js framework, used for building applications with Node.js, has a vulnerability in versions 2.16.2 to prior to 2.16.3 and 3.0.1 to prior to 3.0.3. This issue allows potential attackers to manipulate the Referer header, making it possible for a user’s browser to be redirected to an external, and potentially harmful, website. The flaw arises from the framework incorrectly categorizing some specially crafted URLs as safe relative paths. Exploiting this vulnerability could enable malicious actors to carry out phishing, social engineering, or other redirect-based attacks against Koa.js application users. The issue has been addressed and patched in version 3.0.3.

Affected Version(s)

koa >= 2.16.2, < 2.16.3 < 2.16.2, 2.16.3

koa >= 3.0.1, < 3.0.3 < 3.0.1, 3.0.3

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-62595 : Koa.js Framework Redirect Vulnerability in Node.js