MEDIUM5.0
GHSA-x2rg-q646-7m2v
Koajs vulnerable to Cross-Site Scripting (XSS) at ctx.redirect() function
Quick fix
GHSA-x2rg-q646-7m2v — koa: upgrade to the fixed version with the command below.
npm install koa@2.16.1Details
### Summary In koa < 2.16.1 and < 3.0.0-alpha.5, passing untrusted user input to ctx.redirect() even after sanitizing it, may execute javascript code on the user who use the app.
### Patches This issue is patched in 2.16.1 and 3.0.0-alpha.5.
### PoC Coming soon...
### Impact 1. Redirect user to another phishing site 2. Make request to another endpoint of the application based on user's cookie 3. Steal user's cookie
Are you affected?
Enter the version of the package you're using.