Junglewise Threat Intelligence

CVE-2025-32379: Koajs Cross-Site Scripting in ctx.redirect()

CVE-2025-32379 · Severity: low · CVSS 3.1 · Published 2025-04-09

Technologies: Koajs Koa. Vendors: Koajs.

Executive brief

Koajs is a popular Node.js web application framework used to build web services. A cross-site scripting (XSS) vulnerability in the ctx.redirect() function allows attackers to inject malicious JavaScript code that executes in users' browsers, potentially stealing session cookies, redirecting users to phishing sites, or making unauthorized requests on behalf of authenticated users.

Technical details

The vulnerability is a cross-site scripting (CWE-79) flaw in Koa versions prior to 2.16.1 and 3.0.0-alpha.5. The ctx.redirect() function fails to properly sanitize untrusted user input even when developers attempt to sanitize it, allowing XSS payload injection. The attack vector is network-based and requires user interaction (the user must follow a malicious link or visit an affected page). An attacker can inject JavaScript that executes in the victim's browser context, enabling cookie theft, phishing redirects, or unauthorized API requests. The vulnerability is patched in Koa 2.16.1 and 3.0.0-alpha.5.

Affected products

  • Koajs koa < 2.16.1 and 3.0.0-alpha.1 to < 3.0.0-alpha.5

Timeline

  • 2025-04-09: disclosed: Advisory published (GHSA-x2rg-q646-7m2v)
  • 2025-04-09: patched: Patches released in 2.16.1 and 3.0.0-alpha.5

References

Related threats