AdonisJS HTTP Server Vulnerability in Route Parameter Handling
CVE-2026-107718
6.1MEDIUM
What is CVE-2026-107718?
The AdonisJS HTTP Server experiences a vulnerability due to improper handling of route parameters, which enables unencoded dynamic URL constructs. Specifically, prior to versions 8.2.3 and 9.3.0, the createURL() helper fails to apply encodeURIComponent correctly when incorporating route parameter values. This oversight allows attacker-controlled data to be inserted into URLs, leading to potential redirection to malicious sites from trusted applications. Attackers exploiting this vulnerability can leverage it for phishing attacks or to compromise authentication and OAuth flows. Users should upgrade to the secured versions to mitigate these risks.
Affected Version(s)
http-server < 8.2.3 < 8.2.3
http-server >= 9.0.0, < 9.3.0 < 9.0.0, 9.3.0
