AdonisJS HTTP Server Vulnerability in Route Parameter Handling
CVE-2026-107718

6.1MEDIUM

Key Information:

Vendor

Adonisjs

Vendor
CVE Published:
8 October 2026

What is CVE-2026-107718?

The AdonisJS HTTP Server experiences a vulnerability due to improper handling of route parameters, which enables unencoded dynamic URL constructs. Specifically, prior to versions 8.2.3 and 9.3.0, the createURL() helper fails to apply encodeURIComponent correctly when incorporating route parameter values. This oversight allows attacker-controlled data to be inserted into URLs, leading to potential redirection to malicious sites from trusted applications. Attackers exploiting this vulnerability can leverage it for phishing attacks or to compromise authentication and OAuth flows. Users should upgrade to the secured versions to mitigate these risks.

Affected Version(s)

http-server < 8.2.3 < 8.2.3

http-server >= 9.0.0, < 9.3.0 < 9.0.0, 9.3.0

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.