CVE-2026-107718: Open Redirect Vulnerability in @adonisjs/http-server
Vulnerability ID: CVE-2026-107718
CVSS Score: 6.1
Published: 2026-10-08
CVE-2026-107718 is a medium-severity Open Redirect vulnerability in the core HTTP server package of the AdonisJS Node.js framework. Prior to versions 8.2.3 and 9.3.0, the framework built route paths by directly interpolating dynamic parameters and wildcard segments without URI encoding. If an application routes attacker-controlled input directly to a dynamic first path segment and uses the generated route URL as a redirect destination, a leading slash can produce a scheme-relative external URL. Modern web browsers process scheme-relative URLs by redirecting the client to the specified external domain, exposing users to credential harvesting, social engineering, and session hijacking. This vulnerability affects all applications running unpatched configurations where input validation is not explicitly implemented before generating paths.
TL;DR
Unsanitized interpolation of route parameters in AdonisJS HTTP Server allows remote attackers to force protocol-relative redirects, directing users to external malicious domains.
⚠️ Exploit Status: POC
Technical Details
- CWE ID: CWE-601: URL Redirection to Untrusted Site ('Open Redirect')
- Attack Vector: Network
- CVSS Score: 6.1 (Medium)
- EPSS Score: N/A
- Exploit Status: Proof-of-Concept
- CISA KEV Status: Not Listed
Affected Systems
- AdonisJS Applications utilizing @adonisjs/http-server
-
@adonisjs/http-server: < 8.2.3 (Fixed in:
8.2.3) -
@adonisjs/http-server: >= 9.0.0, < 9.3.0 (Fixed in:
9.3.0)
Code Analysis
Commit: 4548a06
Encode route params and wildcards before building URLs
Commit: ab607a2
Fix dynamic routing and parameter handling verification
Mitigation Strategies
- Upgrade to patched versions of @adonisjs/http-server
- Implement whitelist validation for redirection targets
- Add input validation rules preventing characters like / and \ in parameter input
Remediation Steps:
- Run npm update @adonisjs/http-server to obtain version 8.2.3 or 9.3.0 depending on major branch
- Verify installed version using npm list @adonisjs/http-server
- Ensure that any redirects use explicit domain validation if target routes must accept input parameters
References
- GitHub Security Advisory GHSA-2m6q-8v3h-jqww
- NVD CVE-2026-107718 Detail
- CVE Record CVE-2026-107718
- Framework Release v8.2.3
- Framework Release v9.3.0
- Commit 4548a0631ce2ef1618f04c7b41465be42cad2f7d
- Commit ab607a2958327b6f0019d38f26081e431768877a
Read the full report for CVE-2026-107718 on our website for more details including interactive diagrams and full exploit analysis.
Top comments (0)