-
Notifications
You must be signed in to change notification settings - Fork 5
chore(deps): update dependency koa to v3.0.1 [security] #1018
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
base: main
Are you sure you want to change the base?
Conversation
|
The latest updates on your projects. Learn more about Vercel for GitHub.
|
|
6c26c0b to
a34f909
Compare
a34f909 to
0981434
Compare
0981434 to
3cb0147
Compare
3cb0147 to
023b78d
Compare
023b78d to
728051b
Compare
728051b to
e57d800
Compare
e57d800 to
347fa40
Compare
347fa40 to
be9f355
Compare
be9f355 to
bc853e2
Compare
bc853e2 to
18f773c
Compare
18f773c to
3d73bcb
Compare
3d73bcb to
12fbf10
Compare
12fbf10 to
c6421cc
Compare
c6421cc to
310721c
Compare
310721c to
d716aae
Compare
This PR contains the following updates:
3.0.0→3.0.1GitHub Vulnerability Alerts
CVE-2025-8129
Summary
In the latest version of Koa, the back method used for redirect operations adopts an insecure implementation, which uses the user-controllable referrer header as the redirect target.
Details
on the API document https://www.koajs.net/api/response#responseredirecturl-alt, we can see:
response.redirect(url, [alt])
however, the "back" method is insecure:
Referrer Header is User-Controlled.
PoC
there is a demo for POC:
Proof Of Concept
Impact
https://learn.snyk.io/lesson/open-redirect/
Release Notes
koajs/koa (koa)
v3.0.1Compare Source
What's Changed
422c551Full Changelog: koajs/koa@v3.0.0...v3.0.1
Configuration
📅 Schedule: Branch creation - "" (UTC), Automerge - At any time (no schedule defined).
🚦 Automerge: Enabled.
♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about these updates again.
This PR was generated by Mend Renovate. View the repository job log.