Junglewise Threat Intelligence

CVE-2025-8129: Koa open redirect via referrer header

CVE-2025-8129 · Severity: low · CVSS 3.1 · Published 2025-07-29

Technologies: Koa.

Executive brief

Koa is a popular Node.js web framework used to build web applications and APIs. An attacker can craft a malicious HTTP request with a manipulated referrer header to redirect users to an external website when the application uses Koa's redirect('back') method, potentially enabling phishing attacks or credential theft.

Technical details

This vulnerability is an open redirect (CWE-601) in Koa's response.redirect() method. The vulnerable 'back' option retrieves the redirect URL directly from the user-controlled HTTP Referrer header without validation, allowing attackers to specify arbitrary redirect targets. The attack requires network access and user interaction (the victim must follow the redirect link). An authenticated or unauthenticated attacker can craft requests with malicious Referrer headers to redirect users to attacker-controlled sites. Fixes are available in Koa 2.16.2 and 3.0.1.

Affected products

  • Koa Koa 2.0.0 to 2.16.1, 3.0.0-alpha.0 to 3.0.0

Timeline

  • 2025-07-29: disclosed
  • 2025-07-29: patched: Koa 2.16.2 and 3.0.1 released

References