PT-2026-108247 · Unknown · @Adonisjs/Http-Server
CVE-2026-107718
·
Published
2026-10-08
·
Updated
2026-10-08
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
AdonisJS HTTP Server versions prior to 8.2.3
AdonisJS HTTP Server versions prior to 9.3.0
Description
Route parameter values are inserted into URLs without proper encoding in the shared
createURL() helper, which is utilized by Router.makeUrl() and Response.redirect().toRoute(). When an application uses attacker-controlled data in a dynamic first path segment and employs the resulting URL as a redirect destination, a value starting with a slash can create a scheme-relative external URL. This allows an attacker to redirect users from a trusted application to a malicious site, potentially facilitating phishing or the abuse of authentication and OAuth flows. Wildcard parameters are also affected. This issue does not impact APIs that are designed to intentionally accept complete redirect URLs.Recommendations
Update AdonisJS HTTP Server to version 8.2.3 or later.
Update AdonisJS HTTP Server to version 9.3.0 or later.
Exploit
Fix
Open Redirect
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
@Adonisjs/Http-Server