Koa.js Framework Redirect Vulnerability in Node.js
CVE-2025-62595
What is CVE-2025-62595?
The Koa.js framework, used for building applications with Node.js, has a vulnerability in versions 2.16.2 to prior to 2.16.3 and 3.0.1 to prior to 3.0.3. This issue allows potential attackers to manipulate the Referer header, making it possible for a user’s browser to be redirected to an external, and potentially harmful, website. The flaw arises from the framework incorrectly categorizing some specially crafted URLs as safe relative paths. Exploiting this vulnerability could enable malicious actors to carry out phishing, social engineering, or other redirect-based attacks against Koa.js application users. The issue has been addressed and patched in version 3.0.3.
Affected Version(s)
koa >= 2.16.2, < 2.16.3 < 2.16.2, 2.16.3
koa >= 3.0.1, < 3.0.3 < 3.0.1, 3.0.3