NPM · JULY 2026 · EARLY WARNING

Open Redirect Vulnerability in waku npm Package

EARLY WARNING · UNCONFIRMED. This page describes a developing threat that 0Day surfaced from early signals and has not yet independently confirmed. Details may change. Always verify against the primary sources before acting.
GHSA-43FC-V873-QW85Severity: HIGH

An open redirect vulnerability has been reported in the waku npm package, specifically in the unstable_redirect() helper function. This could potentially allow attackers to redirect users to arbitrary external domains.

What happened

The waku npm package, version 1.0.0-beta.0, appears to have an open redirect vulnerability in its unstable_redirect() helper function. This function reflects user-controlled input into the HTTP Location response header without proper validation. As a result, an attacker could potentially redirect users to arbitrary external domains, enabling phishing attacks and credential theft. It is under investigation whether this vulnerability has been actively exploited. Software engineers using this package should avoid using the unstable_redirect() helper with untrusted input and monitor for updates to the waku package that address this vulnerability. For more details, consult the primary sources.

How 0Day mitigates this

MATCHED TO YOUR ACTUAL DEPENDENCY GRAPH0Day matches every incoming threat signal against your GitHub organization’s full dependency graph, including transitive dependencies. If waku is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.

Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.

Join the 0Day waitlist →

← Back to all threats