PT-2026-108247 · Unknown · @Adonisjs/Http-Server

CVE-2026-107718

·

Published

2026-10-08

·

Updated

2026-10-08

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions AdonisJS HTTP Server versions prior to 8.2.3 AdonisJS HTTP Server versions prior to 9.3.0
Description Route parameter values are inserted into URLs without proper encoding in the shared createURL() helper, which is utilized by Router.makeUrl() and Response.redirect().toRoute(). When an application uses attacker-controlled data in a dynamic first path segment and employs the resulting URL as a redirect destination, a value starting with a slash can create a scheme-relative external URL. This allows an attacker to redirect users from a trusted application to a malicious site, potentially facilitating phishing or the abuse of authentication and OAuth flows. Wildcard parameters are also affected. This issue does not impact APIs that are designed to intentionally accept complete redirect URLs.
Recommendations Update AdonisJS HTTP Server to version 8.2.3 or later. Update AdonisJS HTTP Server to version 9.3.0 or later.

Exploit

Fix

Open Redirect

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-107718
GHSA-2M6Q-8V3H-JQWW

Affected Products

@Adonisjs/Http-Server