GHSA-47p6-69vm-vw6v

Suggest an improvement
Source
https://github.com/advisories/GHSA-47p6-69vm-vw6v
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/05/GHSA-47p6-69vm-vw6v/GHSA-47p6-69vm-vw6v.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-47p6-69vm-vw6v
Aliases
Published
2026-05-26T13:30:54Z
Modified
2026-09-10T03:51:04Z
Severity
  • 7.3 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L CVSS Calculator
  • 5.5 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P CVSS Calculator
Summary
@koa/router has an Access Control Bypass
Details

Versions of the package @koa/router from 14.0.0 and before 15.0.0 are vulnerable to Access Control Bypass due to the middleware being silently dropped from the execution chain when the router prefix contains path parameters. Depending on what the skipped middleware was supposed to protect, an attacker could bypass authentication and authorization, evade rate limiting or bypass input sanitization.

Database specific
{
    "cwe_ids": [
        "CWE-284"
    ],
    "github_reviewed": true,
    "github_reviewed_at": "2026-06-30T17:39:43Z",
    "nvd_published_at": "2026-05-26T07:16:19Z",
    "severity": "MODERATE"
}
References

Affected packages

npm / @koa/router

Package

Name
@koa/router
View open source insights on deps.dev
Purl
pkg:npm/%40koa/router

Affected ranges

Type
SEMVER
Events
Introduced
14.0.0
Fixed
15.0.0

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/05/GHSA-47p6-69vm-vw6v/GHSA-47p6-69vm-vw6v.json"