Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.2
CVE-2025-25200: Koa library can let attackers execute code
CVE-2025-25200 · published 14 days ago
Summary
The Koa web framework used in your projects has a flaw that could let a malicious user run unauthorized commands on your server. This affects the Koa package and its versions used in GitHub Actions, the official koajs/koa repository, and the @rootio/koa distribution. Update to the latest patched version of each Koa package as soon as possible to close the risk.
What to do
- Update koa to version 2.15.4-aikido.4.
- Update GitHub Actions koa to version 2.15.4.
- Update GitHub Actions koa to version 3.0.0-alpha.3.
- Update GitHub Actions koa to version 1.7.1.
- Update GitHub Actions koa to version 0.21.2.
- Update GitHub Actions koa to version 2.15.4-aikido.4.
- Update rootio @rootio/koa to version 2.15.4-root.io.4.
Affected software
| Ecosystem | Vendor | Product | Affected versions |
|---|---|---|---|
| Root:npm | – | koa |
< 2.15.4-aikido.4 Fix: upgrade to 2.15.4-aikido.4
|
| npm | GitHub Actions | koa |
>= 2.0.0, < 2.15.4 >= 3.0.0-alpha.0, < 3.0.0-alpha.3 >= 1.0.0, < 1.7.1 < 0.21.2 Fix: upgrade to 2.15.4
|
| – | koajs | koa |
< 0.21.2 >= 1.0.0, < 1.7.1 >= 2.0.0, < 2.15.4 3.0.0 cpe:2.3:a:koajs:koa:*:*:*:*:*:node.js:*:* |
| Root:npm | GitHub Actions | koa |
< 2.15.4-aikido.4 Fix: upgrade to 2.15.4-aikido.4
|
| Root:npm | rootio | @rootio/koa |
< 2.15.4-root.io.4 Fix: upgrade to 2.15.4-root.io.4
|
Original advisory text
CVE-2025-25200 in koa - Patched by Root
Root has patched CVE-2025-25200 in the koa package for Root:npm. Multiple fixed versions available.
References
- https://nvd.nist.gov/vuln/detail/CVE-2025-25200
- https://github.com/koajs/koa/commit/5054af6e31ffd451a4151a1fe144cef6e5d0d83c
- https://github.com/koajs/koa/commit/5f294bb1c7c8d9c61904378d250439a321bffd32
- https://github.com/koajs/koa/commit/93fe903fc966635a991bcf890cfc3427d33a1a08
- https://github.com/koajs/koa/releases/tag/2.15.4
- https://github.com/advisories/GHSA-593f-38f6-jp5m
- https://github.com/koajs/koa/blob/master/lib/request.js#L259 Product
- https://github.com/koajs/koa/blob/master/lib/request.js#L404 Product
- https://github.com/koajs/koa/security/advisories/GHSA-593f-38f6-jp5m
Severity
9.2
Critical
CVSS 4.0: 9.2 (GHSA)
Exploitation
EPSS <1%
Type
CWE-1333Inefficient Regular Expression Complexity (ReDoS)
Timeline
Published11 Sep 2026
Updated25 Sep 2026
First seen6 Mar 2026
Track software like this
Free during beta