DEV Community

CVE Reports
CVE Reports

Posted on Originally published at cvereports.com

CVE-2026-107718: CVE-2026-107718: Open Redirect Vulnerability in @adonisjs/http-server

CVE-2026-107718: Open Redirect Vulnerability in @adonisjs/http-server

Vulnerability ID: CVE-2026-107718
CVSS Score: 6.1
Published: 2026-10-08

CVE-2026-107718 is a medium-severity Open Redirect vulnerability in the core HTTP server package of the AdonisJS Node.js framework. Prior to versions 8.2.3 and 9.3.0, the framework built route paths by directly interpolating dynamic parameters and wildcard segments without URI encoding. If an application routes attacker-controlled input directly to a dynamic first path segment and uses the generated route URL as a redirect destination, a leading slash can produce a scheme-relative external URL. Modern web browsers process scheme-relative URLs by redirecting the client to the specified external domain, exposing users to credential harvesting, social engineering, and session hijacking. This vulnerability affects all applications running unpatched configurations where input validation is not explicitly implemented before generating paths.

TL;DR

Unsanitized interpolation of route parameters in AdonisJS HTTP Server allows remote attackers to force protocol-relative redirects, directing users to external malicious domains.


⚠️ Exploit Status: POC

Technical Details

  • CWE ID: CWE-601: URL Redirection to Untrusted Site ('Open Redirect')
  • Attack Vector: Network
  • CVSS Score: 6.1 (Medium)
  • EPSS Score: N/A
  • Exploit Status: Proof-of-Concept
  • CISA KEV Status: Not Listed

Affected Systems

  • AdonisJS Applications utilizing @adonisjs/http-server
  • @adonisjs/http-server: < 8.2.3 (Fixed in: 8.2.3)
  • @adonisjs/http-server: >= 9.0.0, < 9.3.0 (Fixed in: 9.3.0)

Code Analysis

Commit: 4548a06

Encode route params and wildcards before building URLs

Commit: ab607a2

Fix dynamic routing and parameter handling verification

Mitigation Strategies

  • Upgrade to patched versions of @adonisjs/http-server
  • Implement whitelist validation for redirection targets
  • Add input validation rules preventing characters like / and \ in parameter input

Remediation Steps:

  1. Run npm update @adonisjs/http-server to obtain version 8.2.3 or 9.3.0 depending on major branch
  2. Verify installed version using npm list @adonisjs/http-server
  3. Ensure that any redirects use explicit domain validation if target routes must accept input parameters

References


Read the full report for CVE-2026-107718 on our website for more details including interactive diagrams and full exploit analysis.

Top comments (0)