CVE-2026-107718

medium

Description

AdonisJS HTTP Server is a package for handling HTTP requests in the AdonisJS framework. Prior to 8.2.3 and 9.3.0, AdonisJS HTTP Server inserts route parameter values into URLs without encodeURIComponent in the shared createURL() helper used by Router.makeUrl() and Response.redirect().toRoute(). If an application places attacker-controlled data in a dynamic first path segment and uses the generated route URL as a redirect destination, a value beginning with a slash can produce a scheme-relative external URL. Wildcard parameters are affected by the same missing encoding, while APIs intentionally accepting complete redirect URLs are not affected. An attacker can redirect users from a trusted application to an attacker-controlled site, facilitating phishing or abuse of authentication and OAuth flows. This issue is fixed in versions 8.2.3 and 9.3.0.

References

https://github.com/adonisjs/http-server/security/advisories/GHSA-2m6q-8v3h-jqww

https://github.com/adonisjs/http-server/releases/tag/v9.3.0

https://github.com/adonisjs/http-server/releases/tag/v8.2.3

https://github.com/adonisjs/http-server/commit/ab607a2958327b6f0019d38f26081e431768877a

https://github.com/adonisjs/http-server/commit/4548a0631ce2ef1618f04c7b41465be42cad2f7d

Details

Source: Mitre, NVD

Published: 2026-10-08

Updated: 2026-10-08

Risk Information

CVSS v2

Base Score: 6.4

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:N

Severity: Medium

CVSS v3

Base Score: 6.1

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Severity: Medium