{"id":"CVE-2025-32379","aliases":["GHSA-x2rg-q646-7m2v"],"url":"https://o3.security/vulnerability/CVE-2025-32379","summary":"XSS at ctx.redirect() function in Koajs","details":"### Summary\nIn koa < 2.16.1 and < 3.0.0-alpha.5, passing untrusted user input to ctx.redirect() even after sanitizing it, may execute javascript code on the user who use the app.\n\n### Patches\nThis issue is patched in  2.16.1 and 3.0.0-alpha.5.\n\n### PoC\nComing soon...\n\n### Impact\n1. Redirect user to another phishing site\n2. Make request to another endpoint of the application based on user's cookie\n3. Steal user's cookie","published":"2025-04-09T15:56:40.574Z","modified":"2026-08-12T03:51:45.226206337Z","cvss":{"score":5,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:L"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"npm","name":"koa","fixedVersion":"2.16.1"},{"ecosystem":"npm","name":"koa","fixedVersion":"3.0.0-alpha.5"}],"fix":{"url":"https://github.com/koajs/koa/commit/ff25eb4a7f2392df46481fe86355161067687312","label":"koajs/koa@ff25eb4"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/32xxx/CVE-2025-32379.json"},{"type":"ADVISORY","url":"https://github.com/koajs/koa/security/advisories/GHSA-x2rg-q646-7m2v"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-32379"},{"type":"FIX","url":"https://github.com/koajs/koa/commit/ff25eb4a7f2392df46481fe86355161067687312"},{"type":"PACKAGE","url":"https://github.com/koajs/koa"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:45.226206337Z"}}