VDB
Sign up
MEDIUM5.0

GHSA-x2rg-q646-7m2v

Koajs vulnerable to Cross-Site Scripting (XSS) at ctx.redirect() function

Quick fix

GHSA-x2rg-q646-7m2v — koa: upgrade to the fixed version with the command below.

npm install koa@2.16.1

Details

### Summary In koa < 2.16.1 and < 3.0.0-alpha.5, passing untrusted user input to ctx.redirect() even after sanitizing it, may execute javascript code on the user who use the app.

### Patches This issue is patched in 2.16.1 and 3.0.0-alpha.5.

### PoC Coming soon...

### Impact 1. Redirect user to another phishing site 2. Make request to another endpoint of the application based on user's cookie 3. Steal user's cookie

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/koa
Introduced in: 0Fixed in: 2.16.1
Fixnpm install koa@2.16.1
npm/koa
Introduced in: 3.0.0-alpha.1Fixed in: 3.0.0-alpha.5
Fixnpm install koa@3.0.0-alpha.5

References