Intel

AIKIDO-2025-10725

koa is vulnerable to Cross-Site Scripting (XSS)

Cross-Site Scripting (XSS)GHSA-C5VW-J4HF-J526 Published Oct 21, 2025

40

Medium Risk

This Affects:

JSkoa
2.16.0 - 3.0.1
Fixed in 3.0.2
Are you affected? Scan for Free

TL;DR

Affected versions of this package are vulnerable to a security misconfiguration in Content-Type header handling, which can lead to Cross-Site Scripting (XSS) attacks. An attacker could exploit this by uploading or serving malicious HTML or SVG files that are interpreted with an incorrect MIME type, allowing arbitrary script execution in users' browsers when the content is viewed.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

koa is vulnerable to Cross-Site Scripting (XSS) in versions 2.16.0 - 3.0.1.

How to fix this

Upgrade the koa library to the patch version.