CVE-2025-62595Medium· 4.3▾ SunlitKoa is expressive middleware for Node.js using ES2017 async functions. In versions 2.16.2 to before 2.16.3 and 3.0.1 to before 3.0.3, a bypass to CVE-2025-8129 was discovered in the Koa.js framework affecting its back redirect functional…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 23.7 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.3%
Koa is expressive middleware for Node.js using ES2017 async functions. In versions 2.16.2 to before 2.16.3 and 3.0.1 to before 3.0.3, a bypass to CVE-2025-8129 was discovered in the Koa.js framework affecting its back redirect functionality. In certain circumstances, an attacker can manipulate the Referer header to force a user’s browser to navigate to an external, potentially malicious website. This occurs because the implementation incorrectly treats some specially crafted URLs as safe relative paths. Exploiting this vulnerability could allow attackers to perform phishing, social engineering, or other redirect-based attacks on users of affected applications. This issue has been patched in version 3.0.3.
koa >= 3.0.1, < 3.0.3koa = 2.16.2Upgrade past the affected range:
koa 3.0.3Connected by shared product, vendor, weakness, or advisory.
CVE-2024-0953Medium· 6.1When a user scans a QR Code with the QR Code Scanner feature, the user is not prompted before being navigated to the page specified in the code
CVE-2026-34442Medium· 5.4FreeScout is a free help desk and shared inbox built with PHP's Laravel framework
CVE-2025-3155High· 7.4A flaw was found in Yelp
CVE-2025-11167Medium· 4.7The CM Registration – Tailored tool for seamless login and invitation-based registrations plugin for WordPress is vulnerable to Open Redirect in all versions up to, and including, 2.5.6
CVE-2025-35059Medium· 4.3Newforma Info Exchange (NIX) '/DownloadWeb/hyperlinkredirect.aspx' provides an unauthenticated URL redirect via the 'nhl' parameter.
CVE-2025-62361Medium· 6.1WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users