Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.2

CVE-2025-25200: Koa library can let attackers execute code

CVE-2025-25200 · published 14 days ago
Summary

The Koa web framework used in your projects has a flaw that could let a malicious user run unauthorized commands on your server. This affects the Koa package and its versions used in GitHub Actions, the official koajs/koa repository, and the @rootio/koa distribution. Update to the latest patched version of each Koa package as soon as possible to close the risk.

What to do
  • Update koa to version 2.15.4-aikido.4.
  • Update GitHub Actions koa to version 2.15.4.
  • Update GitHub Actions koa to version 3.0.0-alpha.3.
  • Update GitHub Actions koa to version 1.7.1.
  • Update GitHub Actions koa to version 0.21.2.
  • Update GitHub Actions koa to version 2.15.4-aikido.4.
  • Update rootio @rootio/koa to version 2.15.4-root.io.4.
Affected software
Ecosystem VendorProductAffected versions
Root:npm – koa < 2.15.4-aikido.4
Fix: upgrade to 2.15.4-aikido.4
npm GitHub Actions koa >= 2.0.0, < 2.15.4
>= 3.0.0-alpha.0, < 3.0.0-alpha.3
>= 1.0.0, < 1.7.1
< 0.21.2
Fix: upgrade to 2.15.4
– koajs koa < 0.21.2
>= 1.0.0, < 1.7.1
>= 2.0.0, < 2.15.4
3.0.0
cpe:2.3:a:koajs:koa:*:*:*:*:*:node.js:*:*
Root:npm GitHub Actions koa < 2.15.4-aikido.4
Fix: upgrade to 2.15.4-aikido.4
Root:npm rootio @rootio/koa < 2.15.4-root.io.4
Fix: upgrade to 2.15.4-root.io.4
Original advisory text
CVE-2025-25200 in koa - Patched by Root
Root has patched CVE-2025-25200 in the koa package for Root:npm. Multiple fixed versions available.
Severity
9.2 Critical
CVSS 4.0: 9.2 (GHSA)
Exploitation
EPSS <1%
Type
CWE-1333Inefficient Regular Expression Complexity (ReDoS)
Timeline
Published11 Sep 2026
Updated25 Sep 2026
First seen6 Mar 2026
Track software like this
Free during beta