CVE-2026-107718
Received Received - Intake

AdonisJS HTTP Server URL Redirect Path Traversal

Vulnerability report for CVE-2026-107718, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-08

Last updated on: 2026-10-08

Assigner: GitHub, Inc.

Description

AdonisJS HTTP Server is a package for handling HTTP requests in the AdonisJS framework. Prior to 8.2.3 and 9.3.0, AdonisJS HTTP Server inserts route parameter values into URLs without encodeURIComponent in the shared createURL() helper used by Router.makeUrl() and Response.redirect().toRoute(). If an application places attacker-controlled data in a dynamic first path segment and uses the generated route URL as a redirect destination, a value beginning with a slash can produce a scheme-relative external URL. Wildcard parameters are affected by the same missing encoding, while APIs intentionally accepting complete redirect URLs are not affected. An attacker can redirect users from a trusted application to an attacker-controlled site, facilitating phishing or abuse of authentication and OAuth flows. This issue is fixed in versions 8.2.3 and 9.3.0.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-08
Last Modified
2026-10-08
Generated
2026-10-09
AI Q&A
2026-10-09
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
adonisjs http-server < 8.2.3
adonisjs http-server >= 9.0.0, < 9.3.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-601 The web application accepts a user-controlled input that specifies a link to an external site, and uses that link in a redirect.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

AdonisJS HTTP Server before versions 8.2.3 and 9.3.0 has a flaw where route parameter values are inserted into URLs without proper encoding. This can allow attackers to manipulate URLs by injecting values starting with slashes, creating scheme-relative external links that redirect users to malicious sites.

Impact Analysis

This vulnerability can lead to phishing attacks where users are tricked into visiting attacker-controlled websites. It may also enable abuse of authentication flows or OAuth processes by redirecting users to malicious destinations.

Mitigation Strategies

Update AdonisJS HTTP Server to version 8.2.3 or 9.3.0 or later to fix the missing encodeURIComponent issue in the createURL() helper.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-107718. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart