AdonisJS: Unencoded route parameters can produce open redirects
Summary
| CVE | CVE-2026-107718 |
|---|---|
| State | PUBLISHED |
| Assigner | GitHub_M |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-10-08 22:17:27 UTC |
| Updated | 2026-10-08 22:17:27 UTC |
| Description | AdonisJS HTTP Server is a package for handling HTTP requests in the AdonisJS framework. Prior to 8.2.3 and 9.3.0, AdonisJS HTTP Server inserts route parameter values into URLs without encodeURIComponent in the shared createURL() helper used by Router.makeUrl() and Response.redirect().toRoute(). If an application places attacker-controlled data in a dynamic first path segment and uses the generated route URL as a redirect destination, a value beginning with a slash can produce a scheme-relative external URL. Wildcard parameters are affected by the same missing encoding, while APIs intentionally accepting complete redirect URLs are not affected. An attacker can redirect users from a trusted application to an attacker-controlled site, facilitating phishing or abuse of authentication and OAuth flows. This issue is fixed in versions 8.2.3 and 9.3.0. |
Risk And Classification
Primary CVSS: v3.1 6.1 MEDIUM from [email protected]
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Problem Types: CWE-601 | CWE-601 CWE-601: URL Redirection to Untrusted Site ('Open Redirect')
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.1 | [email protected] | Secondary | 6.1 | MEDIUM | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
| 3.1 | CNA | DECLARED | 6.1 | MEDIUM | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
CVSS v3.1 Breakdown
Attack Vector
NetworkAttack Complexity
LowPrivileges Required
NoneUser Interaction
RequiredScope
ChangedConfidentiality
LowIntegrity
LowAvailability
NoneCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Adonisjs | Http-server | affected < 8.2.3 | Not specified |
| CNA | Adonisjs | Http-server | affected >= 9.0.0, < 9.3.0 | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| github.com/adonisjs/http-server/commit/4548a0631ce2ef1618f04c7b41465be42... | [email protected] | github.com | |
| github.com/adonisjs/http-server/security/advisories/GHSA-2m6q-8v3h-jqww | [email protected] | github.com | |
| github.com/adonisjs/http-server/releases/tag/v9.3.0 | [email protected] | github.com | |
| github.com/adonisjs/http-server/releases/tag/v8.2.3 | [email protected] | github.com | |
| github.com/adonisjs/http-server/commit/ab607a2958327b6f0019d38f26081e431... | [email protected] | github.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.